CVE-2022-27247

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.
References
Link Resource
https://myses.de/#about Third Party Advisory
https://myses.de/pdf/CVE2022-27247.pdf Exploit Third Party Advisory
https://myses.de/#about Third Party Advisory
https://myses.de/pdf/CVE2022-27247.pdf Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*

History

21 Nov 2024, 06:55

Type Values Removed Values Added
References () https://myses.de/#about - Third Party Advisory () https://myses.de/#about - Third Party Advisory
References () https://myses.de/pdf/CVE2022-27247.pdf - Exploit, Third Party Advisory () https://myses.de/pdf/CVE2022-27247.pdf - Exploit, Third Party Advisory

Information

Published : 2022-05-13 15:15

Updated : 2024-11-21 06:55


NVD link : CVE-2022-27247

Mitre link : CVE-2022-27247

CVE.ORG link : CVE-2022-27247


JSON object : View

Products Affected

cdsoft

  • winhotel.mx
CWE
CWE-639

Authorization Bypass Through User-Controlled Key