๐Ÿ” CVE Alert

CVE-2025-14200

LOW 3.5

alokjaiswal Hotel-Management-services-using-MYSQL-and-php Request Pending usersub.php cross site scripting

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected is an unknown function of the file /usersub.php of the component Request Pending Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-79 CWE-94
Vendor alokjaiswal
Product hotel-management-services-using-mysql-and-php
Published Dec 7, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for alokjaiswal hotel-management-services-using-mysql-and-php

Be the first to know when new low vulnerabilities affecting alokjaiswal hotel-management-services-using-mysql-and-php are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

alokjaiswal / Hotel-Management-services-using-MYSQL-and-php
5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.334620 vuldb.com: https://vuldb.com/?ctiid.334620 vuldb.com: https://vuldb.com/?submit.699993 github.com: https://github.com/Yh276/h0202/blob/main/Hotel-Management-services-using-MYSQL-and-php%20web%202xxs.docx

Credits

๐Ÿ” 0202h (VulDB User)