๐Ÿ” CVE Alert

CVE-2025-14201

LOW 2.4

alokjaiswal Hotel-Management-services-using-MYSQL-and-php dishsub.php cross site scripting

CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in alokjaiswal Hotel-Management-services-using-MYSQL-and-php up to 5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f. Affected by this vulnerability is an unknown functionality of the file /dishsub.php. The manipulation of the argument item.name results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-79 CWE-94
Vendor alokjaiswal
Product hotel-management-services-using-mysql-and-php
Published Dec 7, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for alokjaiswal hotel-management-services-using-mysql-and-php

Be the first to know when new low vulnerabilities affecting alokjaiswal hotel-management-services-using-mysql-and-php are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

alokjaiswal / Hotel-Management-services-using-MYSQL-and-php
5f8b60a7aa6c06a5632de569d4e3f6a8cd82f76f

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.334621 vuldb.com: https://vuldb.com/?ctiid.334621 vuldb.com: https://vuldb.com/?submit.699994 github.com: https://github.com/Yh276/h0202/blob/main/Hotel-Management-services-using-MYSQL-and-php%20web%201%20xxs.docx

Credits

๐Ÿ” 0202h (VulDB User)