The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Hoteldruid | Digitaldruid | 3.0.3 (including) | 3.0.3 (including) | 
| Hoteldruid | Ubuntu | bionic | * | 
| Hoteldruid | Ubuntu | focal | * | 
| Hoteldruid | Ubuntu | impish | * | 
| Hoteldruid | Ubuntu | kinetic | * | 
| Hoteldruid | Ubuntu | upstream | * |