VulnerabilityModified
CVE-2021-42948
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
LOW 3.7EPSS 0.72%
Does this matter?
Lower severity and a low EPSS score (0.72%). Track it; it rarely justifies an emergency change on its own.
Description
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
- CVSS 3.1
- 3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- digitaldruid/hoteldruid
- Source
- cve@mitre.org
References
- https://github.com/dhammon/HotelDruid-CVE-2021-42948Third Party Advisory
- https://github.com/dhammon/SecurityBroken Link
- https://www.hoteldruid.com/Product, Vendor Advisory
- https://github.com/dhammon/HotelDruid-CVE-2021-42948Third Party Advisory
- https://github.com/dhammon/SecurityBroken Link
- https://www.hoteldruid.com/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.