{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-14725", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-07-04T08:06:32.108Z", "datePublished": "2026-07-05T08:00:08.967Z", "dateUpdated": "2026-07-07T02:46:18.393Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-07-05T08:00:08.967Z" }, "title": "SourceCodester Online Boat Reservation System session expiration", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-613", "lang": "en", "description": "Session Expiration" } ] } ], "affected": [ { "vendor": "SourceCodester", "product": "Online Boat Reservation System", "versions": [ { "version": "1.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:sourcecodester:online_boat_reservation_system:*:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 6.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 6.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 6.5, "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-07-04T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-07-04T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-07-04T10:11:36.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "Hemant Raj Bhati (VulDB User)", "type": "reporter" } ], "references": [ { "url": "https://vuldb.com/vuln/376311", "name": "VDB-376311 | SourceCodester Online Boat Reservation System session expiration", "tags": [ "vdb-entry" ] }, { "url": "https://vuldb.com/vuln/376311/cti", "name": "VDB-376311 | CTI Indicators (IOB, IOC)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-14725", "name": "CVE-2026-14725 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/847674", "name": "Submit #847674 | SourceCodester Online Boat Reservation System 1.0 Improper Session Invalidation", "tags": [ "third-party-advisory" ] }, { "url": "https://medium.com/@hemantrajbhati5555/improper-session-invalidation-in-online-boat-reservation-system-using-php-acebd53a8ae7", "tags": [ "broken-link", "exploit" ] }, { "url": "https://www.sourcecodester.com/", "tags": [ "product" ] } ], "tags": [ "x_freeware" ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-07-07T02:46:05.704992Z", "id": "CVE-2026-14725", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-07T02:46:18.393Z" } } ] } }