Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-87g3-rx63-rrch

Опубликовано: 17 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

EPSS

Процентиль: 97%
0.36793
Средний

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-326

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

CVSS3: 9.8
nvd
больше 3 лет назад

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

CVSS3: 9.8
debian
больше 3 лет назад

The component controlla_login function in HotelDruid Hotel Management ...

EPSS

Процентиль: 97%
0.36793
Средний

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-326