I tested the XSS vulnerability in the /view/user.php directory of the project and found that a popup XSS can be triggered in the nickname field.   Project URL https://github.com/FantasticLBP/Hotels_Server
I tested the XSS vulnerability in the /view/user.php directory of the project and found that a popup XSS can be triggered in the nickname field.

Project URL
https://github.com/FantasticLBP/Hotels_Server