Sceawere
Vulnerability Detail
CVE-2026-94668UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Salon Booking
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Dimitri Grassi
- Product
- Salon booking system
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Reflected XSS.This issue affects Salon booking system: from n/a through 10.31.5.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:41.957Z",
"pubdate": "2026-10-09T10:16:41.957Z",
"executiveSummary": "The Salon booking system is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability, affecting versions n/a through 10.31.5, allows remote, unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThe primary risk involves the compromise of user sessions, potential theft of sensitive session tokens, and unauthorized actions performed on behalf of authenticated administrators or clients.\nAs a Reflected XSS vulnerability, the attack requires the victim to interact with a malicious link crafted by the attacker. No prior authentication is required to initiate the attack, making it a critical concern for web application integrity and user security.\nSuccessful exploitation bypasses the same-origin policy, allowing the attacker to manipulate the Document Object Model (DOM), perform unauthorized operations, or redirect users to malicious endpoints.",
"technicalDetails": "The vulnerability resides within the input handling mechanisms of the Salon booking system, specifically where user-provided query parameters or form inputs are reflected back to the browser without adequate sanitization or output encoding.\nThe root cause is the failure of the application to properly neutralize characters that carry special meaning in HTML, such as <, >, \", and ', prior to embedding them into the HTTP response body.\nThe attack flow begins when an attacker identifies a vulnerable parameter that is reflected in the application's response. The attacker crafts a malicious URL containing a JavaScript payload (e.g., <script>alert(document.cookie)</script>) within the susceptible parameter.\nWhen an unsuspecting victim clicks the malicious link, the browser sends a request to the server. The server processes the request and includes the unsanitized malicious script in the generated HTML page.\nUpon receipt of the HTTP response, the victim's browser interprets the injected string as executable code rather than plain text. Consequently, the payload executes within the security context of the origin site.\nBecause the payload runs in the context of the site, it gains access to the Document Object Model, enabling the execution of actions such as reading sensitive session cookies, hijacking user accounts, or modifying the displayed content of the booking system page to perform phishing.\nThe impact is significant as it facilitates 'man-in-the-browser' style attacks, where the attacker leverages the trust established between the user's browser and the legitimate Salon booking system.\nThis vulnerability affects versions 10.31.5 and earlier. There is no requirement for the attacker to have administrative privileges; the attack is triggered purely via client-side interaction through a malicious URI.\nThe lack of context-aware output encoding remains the fundamental flaw, as the application assumes user input is benign and fails to apply secure coding standards such as those recommended by OWASP for preventing XSS."
}