Description
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
Published: 2026-02-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (remote)
Action: Apply Patch
AI Analysis

Impact

A flaw in SourceCodester Simple Responsive Tourism Website 1.0 exists in the registration handling script Master.php. Manipulating the firstname, lastname or username input fields injects arbitrary client‑side script into the page rendered after registration. The vulnerability enables remote execution of that script when a user visits the resulting page, and published exploit code confirms the flaw can be used from outside the system.

Affected Systems

The affected vendor is SourceCodester and the product is Simple Responsive Tourism Website version 1.0. No other versions or sub‑products are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation is possible remotely via HTTP requests that supply malicious values to the registration endpoint, and the existence of publicly available exploit code demonstrates feasibility.

Generated by OpenCVE AI on April 18, 2026 at 13:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied update that resolves the XSS flaw, or upgrade to a newer release if available.
  • Implement server‑side input validation and output encoding for all user‑supplied registration fields to prevent injection of client‑side code.
  • Add a Content Security Policy header that restricts script execution or deploy a Web Application Firewall configured to block malicious script payloads.

Generated by OpenCVE AI on April 18, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Oretnom23
Oretnom23 simple Responsive Tourism Website
CPEs cpe:2.3:a:oretnom23:simple_responsive_tourism_website:1.0:*:*:*:*:*:*:*
Vendors & Products Oretnom23
Oretnom23 simple Responsive Tourism Website

Mon, 09 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester simple Responsive Tourism Website
Vendors & Products Sourcecodester
Sourcecodester simple Responsive Tourism Website

Sun, 08 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
Title SourceCodester Simple Responsive Tourism Website Registration Master.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Oretnom23 Simple Responsive Tourism Website
Sourcecodester Simple Responsive Tourism Website
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:43:33.428Z

Reserved: 2026-02-07T08:55:17.881Z

Link: CVE-2026-2159

cve-icon Vulnrichment

Updated: 2026-02-09T21:13:35.523Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-08T16:15:50.207

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-2159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T13:15:25Z

Weaknesses