CVE-2022-27247

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.
References
Link Resource
https://myses.de/#about Third Party Advisory
https://myses.de/pdf/CVE2022-27247.pdf Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*

Information

Published : 2022-05-13 08:15

Updated : 2022-05-24 09:03


NVD link : CVE-2022-27247

Mitre link : CVE-2022-27247


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

Advertisement

dedicated server usa

Products Affected

cdsoft

  • winhotel.mx