Описание
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
Ссылки
- Third Party Advisory
- Broken Link
- ProductVendor Advisory
- Third Party Advisory
- Broken Link
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.3 (включая)
cpe:2.3:a:digitaldruid:hoteldruid:*:*:*:*:*:*:*:*
EPSS
Процентиль: 40%
0.00185
Низкий
3.7 Low
CVSS3
Дефекты
CWE-319
Связанные уязвимости
CVSS3: 3.7
ubuntu
больше 3 лет назад
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
CVSS3: 3.7
debian
больше 3 лет назад
HotelDruid Hotel Management Software v3.0.3 and below was discovered t ...
CVSS3: 3.7
github
больше 3 лет назад
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
EPSS
Процентиль: 40%
0.00185
Низкий
3.7 Low
CVSS3
Дефекты
CWE-319