CVE Vulnerabilities

CVE-2021-42949

Improper Authentication

Published: Sep 16, 2022 | Modified: Aug 08, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Hoteldruid Digitaldruid 3.0.3 (including) 3.0.3 (including)
Hoteldruid Ubuntu bionic *
Hoteldruid Ubuntu impish *
Hoteldruid Ubuntu kinetic *
Hoteldruid Ubuntu upstream *

Potential Mitigations

References