Description
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Published: 2026-06-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in SourceCodester Online Boat Reservation System 1.0 allows attackers to bypass proper authorization checks on administrative endpoints. Because the system treats requests to these endpoints as authorized without verifying user identity or roles, a remote adversary can perform privileged actions that should be restricted to administrators. The flaw is classified under CWE-266 and CWE-285 and has a CVSS base score of 5.3, indicating a moderate risk if exploited. The vulnerability is exploitable from any client that can reach the affected endpoints, and the publicly disclosed exploit demonstrates that the flaw can be used to perform unauthorized administrative operations.

Affected Systems

This issue affects the SourceCodester Online Boat Reservation System product, specifically version 1.0. No other product versions are known to be impacted; the product is referenced by the vendor as sourcecodester:online_boat_reservation_system. The attack surface includes multiple administrative endpoints within the application, allowing broad misuse if not mitigated.

Risk and Exploitability

Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the remote nature of the attack and the ability to tamper with multiple endpoints represent a tangible threat to confidentiality and integrity. The CVSS score of 5.3 and lack of restrictions on the affected interfaces suggest that a determined attacker could exploit this flaw to gain unauthorized administrative privileges, potentially altering reservations, accessing sensitive user data, or modifying system configuration. Patch or mitigation is recommended before any evidence of exploitation is observed.

Generated by OpenCVE AI on June 3, 2026 at 03:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-released patch or update to the latest version of SourceCodester Online Boat Reservation System that fixes the authorization validation on administrative endpoints.
  • Restrict network access to administrative endpoints using firewall rules or VPN to ensure only trusted administrators can reach them.
  • Verify that role-based access control checks are correctly enforced for all administrative functions, ensuring that users without administrative privileges cannot invoke these endpoints.
  • Monitor logs for repeated or unauthorized access attempts to administrative URLs and investigate any suspicious activity.

Generated by OpenCVE AI on June 3, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Title SourceCodester Online Boat Reservation System Administrative Endpoint improper authorization
First Time appeared Sourcecodester
Sourcecodester online Boat Reservation System
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:sourcecodester:online_boat_reservation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Boat Reservation System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Boat Reservation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-03T14:07:35.177Z

Reserved: 2026-06-02T15:44:47.102Z

Link: CVE-2026-10693

cve-icon Vulnrichment

Updated: 2026-06-03T13:17:47.639Z

cve-icon NVD

Status : Received

Published: 2026-06-03T01:16:21.783

Modified: 2026-06-03T01:16:21.783

Link: CVE-2026-10693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T10:54:15Z

Weaknesses