PT-2026-46977 · Sourcecodester · Ship Ferry Ticket Reservation System
CVE-2026-11338
·
Published
2026-06-05
·
Updated
2026-06-05
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Ship Ferry Ticket Reservation System version 1.0
Description
Cross site scripting is possible via remote attack through the manipulation of the
Username argument in the '/admin/?page=user/manage user' endpoint. Cross site scripting is a flaw that allows an attacker to inject malicious scripts into web pages viewed by other users.Recommendations
Update SourceCodester Ship Ferry Ticket Reservation System version 1.0 to a version that contains a fix. As a temporary workaround, restrict access to the '/admin/?page=user/manage user' endpoint or avoid using the
Username argument until the issue is resolved.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ship Ferry Ticket Reservation System