Impact
A flaw in the application’s session handling logic enables an attacker to manipulate session data, causing the system to terminate or expire user sessions prematurely. The vulnerability is classified as an Improper Session Handling weakness (CWE‑613).
Affected Systems
SourceCodester Online Boat Reservation System is affected; specific version information is not provided in the CVE payload; no other releases or derivative builds are mentioned as impacted by the CNA.
Risk and Exploitability
The base CVSS score of 5.3 indicates a moderate severity, while an EPSS score of < 1% reflects a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely from anywhere over the network, and a publicly available exploitation code is accessible.
OpenCVE Enrichment