PatchSiren cyber security CVE debrief
CVE-2026-5705 code-projects CVE debrief
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 and is considered Low severity. Users of Online Hotel Booking 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it.
- Vendor
- code-projects
- Product
- Online Hotel Booking
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Users of Online Hotel Booking 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it. This includes applying vendor patches if available, implementing compensating controls such as input validation and output encoding, and monitoring for suspicious activity and exception tracking. System administrators and security teams responsible for Online Hotel Booking 1.0 deployments should prioritize this vulnerability based on its CVSS score and potential impact.
Technical summary
The vulnerability is located in the /booknow.php file of the Online Hotel Booking 1.0 system, specifically in the roomname parameter. An attacker can inject malicious scripts into this parameter, allowing for cross site scripting attacks. The attack can be launched remotely. The CVSS score of 2.1 indicates a Low severity vulnerability. There is no information available on how to exploit this vulnerability beyond the publicly available exploit.
Defensive priority
Low priority due to CVSS score of 2.1.
Recommended defensive actions
- Inventory affected systems and apply vendor patches if available.
- Implement compensating controls such as input validation and output encoding.
- Monitor for suspicious activity and exception tracking.
- Review system logs for unusual patterns that could indicate exploitation.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record was published on 2026-04-07T00:16:21.440Z and has not been modified since then. The NVD entry is currently Deferred. There is no additional information available about the vulnerability beyond what is provided in the CVE record and NVD entry. Users should verify the accuracy of this information with the vendor or other sources. Defensive verification tasks include reviewing system logs for suspicious activity and checking for any unusual patterns that could indicate exploitation.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T00:16:21.440Z and has not been modified since then.