The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hoteldruid | Digitaldruid | 3.0.3 (including) | 3.0.3 (including) |
Hoteldruid | Ubuntu | bionic | * |
Hoteldruid | Ubuntu | impish | * |
Hoteldruid | Ubuntu | kinetic | * |
Hoteldruid | Ubuntu | upstream | * |