PHPJabbers Restaurant Booking System Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in PHPJabbers Restaurant Booking System version 3.0. This issue occurs in the Reservations menu, specifically within the Schedule section's date parameter. The vulnerability allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the date parameter.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, log into the application and navigate to the Reservations menu. Click on the Print option, and then inject an XSS payload into the 'date' parameter. The injected script will be executed, resulting in an XSS popup.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
