S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-42663 Scanner

CVE-2021-42663 scanner - Cross-Site Scripting (XSS) vulnerability in Sourcecodester Online Event Booking and Reservation System

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-42663
4.3
CVSS

An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Sourcecodester Online Event Booking and Reservation System is a PHP/MySQL based web application used for booking and managing event reservations online. It is designed to help event organizers provide a smooth and hassle-free experience to their customers who wish to book their services online. The system offers various features such as booking management, payment processing, and real-time inventory management. 

Recently, the system was found to have a severe vulnerability that allows attackers to inject malicious HTML code into the system via the 'msg' parameter in the /event-management/index.php page. This vulnerability has been identified as CVE-2021-42663. Attackers can exploit this vulnerability to change the visibility of the website and trick users into clicking on a link that directs them to the attacker's site, exposing them to further cyber-attacks.

If left unaddressed, this vulnerability could lead to a series of devastating consequences, such as data theft, website defacement, and reputational damage to event organizers who use the system. Attackers can exploit this vulnerability to access sensitive user data, potentially leading to identity theft and fraud. They can also take control of the website and use it to distribute malware or launch a phishing campaign.

At s4e.io, we provide cutting-edge security solutions that help businesses and individuals secure their digital assets. Our pro features include vulnerability scanning, web application and network security testing, and penetration testing. By leveraging our platform, you can identify and remediate vulnerabilities in your digital assets proactively, ensuring that your systems remain safe from attacks at all times. 

 

REFERENCES

Solution Advice

To ensure that your Sourcecodester Online Event Booking and Reservation System is not vulnerable to this attack, you need to take a series of precautions:

  • Ensure that all system components are up-to-date and patched.
  • Implement proper access controls to limit access to sensitive data.
  • Use secure coding practices to prevent injection attacks.
  • Implement web application firewalls and intrusion detection systems.
  • Conduct regular security assessments and penetration testing to identify vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-42663 scanner - Cross-Site Scripting (XSS) vulnerability in Sourcecodester Online Event Booking and Reservation System | S4E