Description
A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Published: 2026-07-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the application’s session handling logic enables an attacker to manipulate session data, causing the system to terminate or expire user sessions prematurely. The vulnerability is classified as an Improper Session Handling weakness (CWE‑613).

Affected Systems

SourceCodester Online Boat Reservation System is affected; specific version information is not provided in the CVE payload; no other releases or derivative builds are mentioned as impacted by the CNA.

Risk and Exploitability

The base CVSS score of 5.3 indicates a moderate severity, while an EPSS score of < 1% reflects a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely from anywhere over the network, and a publicly available exploitation code is accessible.

Generated by OpenCVE AI on July 23, 2026 at 15:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch or update for SourceCodester Online Boat Reservation System to correct the session handling logic.
  • If no patch is available, review the application’s session expiration code to ensure sessions end only upon explicit logout and are not prematurely invalidated by outside input.
  • Enable secure cookie attributes, such as HttpOnly and Secure flags, and enforce HTTPS to mitigate session hijacking or fixation risks.

Generated by OpenCVE AI on July 23, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Title SourceCodester Online Boat Reservation System session expiration
First Time appeared Sourcecodester
Sourcecodester online Boat Reservation System
Weaknesses CWE-613
CPEs cpe:2.3:a:sourcecodester:online_boat_reservation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Boat Reservation System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Boat Reservation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-07T02:46:18.393Z

Reserved: 2026-07-04T08:06:32.108Z

Link: CVE-2026-14725

cve-icon Vulnrichment

Updated: 2026-07-07T02:46:13.952Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T16:00:14Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration