Hotels Server Project
Hotels Server Project Hotels Server: vulnerabilidades y CVE
Hotels Server Project Hotels Server tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-33948 | Crítica (9.8) | 0.82% | — | 17 feb 2023 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. |
| CVE-2020-18102 | Media (6.1) | 1.2% | — | 10 may 2021 | Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php". |
| CVE-2019-8393 | Crítica (9.8) | 1.1% | — | 17 feb 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled. |
| CVE-2019-7648 | Alta (7.5) | 0.94% | — | 8 feb 2019 | controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage. |
| CVE-2019-6497 | Crítica (9.8) | 1.0% | — | 20 ene 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. |