CVE-2019-7554: API Based Travel Booking Project API Based Travel Booking

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-results.php d2 parameter.

Affected products

Published 2019-06-06. Last modified 2026-06-17.