CVE-2026-3763 - Vulnerability Analysis
MediumCVSS: 4.3Last Updated: March 9, 2026
code-projects Simple Flight Ticket Booking System - Stored XSS
Published: March 8, 2026Updated: March 9, 2026PoC AvailableRemote Exploitable
Overview
code-projects Simple Flight Ticket Booking System 1.0 contains a stored XSS caused by input manipulation in showhistory.php, letting remote attackers execute scripts, exploit requires crafted input.
Severity & Score
Severity: Medium
CVSS Score: 4.3
Impact
Remote attackers can execute scripts in users' browsers, potentially stealing session data or performing actions on behalf of users.
Mitigation
Update to the latest version or apply patches to sanitize inputs in showhistory.php.
References
Related Resources
Details
- CVE ID
- CVE-2026-3763
- Severity
- Medium
- CVSS Score
- 4.3
- Type
- stored_xss
- Status
- confirmed
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N