PT-2022-11749 · Unknown+1 · Hoteldruid Hotel Management+1

Published

2022-09-16

·

Updated

2022-09-17

·

CVE-2021-42948

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HotelDruid Hotel Management Software versions v3.0.3 and earlier
Description The issue concerns exposed session tokens in multiple links via GET parameters, allowing attackers to access user session identifiers.
Recommendations For HotelDruid Hotel Management Software versions v3.0.3 and earlier, consider restricting access to sensitive links and parameters to minimize the risk of session token exposure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42948

Affected Products

Debian
Hoteldruid Hotel Management