CVE Details
Basic Information
| Title |
Summer Pearl Group Vacation Rental Management Platform updateListing cross site scripting |
| Type |
cve |
| Published |
2025-05-26T10:31:04.786Z |
| Last Seen |
|
Product Information
| Vendor |
Summer Pearl Group |
| Product |
Vacation Rental Management Platform |
| Version |
1.0.0 |
CVSS Information
| Base Score |
5.1 (MEDIUM) |
| Attack Vector |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
The Summer Pearl Group Vacation Rental Management Platform up to version 1.0.1 is vulnerable to cross-site scripting (XSS) via the spgLsTitle parameter in the /spgpm/updateListing endpoint. This allows remote attackers to inject malicious scripts that can be executed in the context of the user’s browser. The vulnerability has a CVSS score of 5.1 and is considered Medium severity. Upgrading to version 1.0.2 resolves the issue. |
| AI Severity |
Medium |
| Vendor |
Summer Pearl Group |
| Product |
Vacation Rental Management Platform |
| Affected Version |
1.0.0, 1.0.1 |
Additional Information
| CVE List |
|
| CWE List |
CWE-79, CWE-94 |
| Bulletin Family |
|
| Source Data |
Summer Pearl Group Vacation Rental Management Platform 1.0.0
Summer Pearl Group Vacation Rental Management Platform 1.0.1 |
Source Information
| Source Data |
Summer Pearl Group Vacation Rental Management Platform 1.0.0
Summer Pearl Group Vacation Rental Management Platform 1.0.1 |
| Source Link |
|
Description
A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. This affects an unknown part of the file /spgpm/updateListing. The manipulation of the argument spgLsTitle leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Score Summary
View Full CVE Details