PatchSiren cyber security CVE debrief
CVE-2026-5705 code-projects CVE debrief
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 and is considered Low severity. Users of Online Hotel Booking 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it.
- Vendor
- code-projects
- Product
- Online Hotel Booking
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Users of Online Hotel Booking 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it. This includes applying vendor patches if available, implementing compensating controls such as input validation and output encoding, and monitoring for suspicious activity and exception tracking. System administrators and security teams responsible for Online Hotel Booking 1.0 deployments should prioritize this vulnerability based on its CVSS score and potential impact.
Technical summary
The vulnerability is located in the /booknow.php file of the Online Hotel Booking 1.0 system, specifically in the roomname parameter. An attacker can inject malicious scripts into this parameter, allowing for cross site scripting attacks. The attack can be launched remotely. The CVSS score of 2.1 indicates a Low severity vulnerability. There is no information available on how to exploit this vulnerability beyond the publicly available exploit.
Defensive priority
Low priority due to CVSS score of 2.1.
Recommended defensive actions
- Inventory affected systems and apply vendor patches if available.
- Implement compensating controls such as input validation and output encoding.
- Monitor for suspicious activity and exception tracking.
- Review system logs for unusual patterns that could indicate exploitation.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record was published on 2026-04-07T00:16:21.440Z and has not been modified since then. The NVD entry is currently Deferred. There is no additional information available about the vulnerability beyond what is provided in the CVE record and NVD entry. Users should verify the accuracy of this information with the vendor or other sources. Defensive verification tasks include reviewing system logs for suspicious activity and checking for any unusual patterns that could indicate exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5705 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5705
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5705 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5705
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://code-projects.org/
-
Source reference
Unverified legacy reference
URL: https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Reflected%20Cross-Site%20Scripting%20(XSS)%20in%20Online%20Hotel%20Booking%20System%20roomname%20Parameter.md
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/786325
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/355521
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/355521/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.