PT-2025-1510 · Kwhotel · Kwhotel

6En6Ar

·

Published

2025-01-23

·

Updated

2025-02-07

·

CVE-2023-46400

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KWHotel version 0.47
Description The issue concerns CSV Formula Injection in the add guest function. This allows for potential exploitation through crafted CSV formulas. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For KWHotel version 0.47, consider restricting access to the add guest function until a fix is available. As a temporary workaround, avoid using the add guest function with untrusted input to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46400

Affected Products

Kwhotel