NA

CVE-2021-42948

Published: 16/09/2022 Updated: 17/09/2022
CVSS v3 Base Score: 3.7 | Impact Score: 1.4 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

HotelDruid Hotel Management Software v3.0.3 and below exists to have exposed session tokens in multiple links via GET parameters, allowing malicious users to access user session id's.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digitaldruid hoteldruid

Github Repositories

CVE-2021-42948 HotelDruid Hotel Management Software v303 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's The session token used to access authenticated pages of the application is passed using GET methods generated from the headphp file The headphp file creates the applicati

TryHackMe HotelKiosk Official Writeup I created the HotelKiosk box on TryHackMe to highlight my first two CVEs (CVE-2021-42949 and CVE-2021-42948) found from inspiration through TheMayor's blog post I Was Bored One NIght and Found Two CVEs I also drew inspiration from John Hammond's Kiosk Breakout YouTube series where he covers the setup and escape of Windows native