CVE-2026-13499 Details
Description
A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
A cross-site scripting (XSS) vulnerability has been identified in the Yash Pokharna Restaurant Management System, specifically within the Registration Handler component. The issue arises in the login_register.php file, where the Username argument is manipulated, leading to the execution of malicious scripts. This vulnerability can be exploited remotely. The application follows a rolling release model, making it difficult to pinpoint specific affected versions. The project has been notified of this vulnerability but has not yet responded.
It is recommended to sanitize usernames during registration to prevent the inclusion of HTML tags and to apply output encoding using 'htmlspecialchars()' before rendering usernames in the HTML.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 28, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/yashpokharna2555/restaurent-management-system/ | [email protected] | Source CodeVendor |
| https://github.com/yashpokharna2555/restaurent-management-system/issues/4 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-13499 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/838560 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/374494 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/374494/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| yashpokharna2555 restaurent-management-system | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 28, 2026 | New CVE Received | [email protected] |
Volerion