CVE-2025-63949
EUVD-2025-20432618.12.2025, 21:15
A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.
Awaiting analysis
This vulnerability is currently awaiting analysis.