CVE-2022-27247

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.
References
Link Resource
https://myses.de/#about Third Party Advisory
https://myses.de/pdf/CVE2022-27247.pdf Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*

History

24 May 2022, 16:03

Type Values Removed Values Added
References (MISC) https://myses.de/#about - (MISC) https://myses.de/#about - Third Party Advisory
References (MISC) https://myses.de/pdf/CVE2022-27247.pdf - (MISC) https://myses.de/pdf/CVE2022-27247.pdf - Exploit, Third Party Advisory
CWE CWE-639
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
CPE cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*

13 May 2022, 15:31

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-13 15:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-27247

Mitre link : CVE-2022-27247

CVE.ORG link : CVE-2022-27247


JSON object : View

Products Affected

cdsoft

  • winhotel.mx
CWE
CWE-639

Authorization Bypass Through User-Controlled Key