CVE-2026-2159 | SourceCodester Simple Responsive Tourism Website 1.0 Registration Master.php?f=register firstname/lastname/username cross site scripting (EUVD-2026-5790)
A vulnerability described as problematic has been identified in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting.
This vulnerability is registered as CVE-2026-2159. It is possible to launch the attack remotely. Furthermore, an exploit is available.