Known Vulnerabilities for Hotels Server by Hotels Server Project
Listed below are 5 of the newest known vulnerabilities associated with "Hotels Server" by "Hotels Server Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-33948 json | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username par... | 9.8 - CRITICAL | 2023-02-17 | 2023-02-28 |
| CVE-2020-18102 json | Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted comma... | 6.1 - MEDIUM | 2021-05-10 | 2021-05-18 |
| CVE-2019-8393 json | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mi... | 9.8 - CRITICAL | 2019-02-17 | 2019-02-20 |
| CVE-2019-7648 json | controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to prote... | 7.5 - HIGH | 2019-02-08 | 2020-08-24 |
| CVE-2019-6497 json | Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. | 9.8 - CRITICAL | 2019-01-20 | 2019-01-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hotels Server Project | Hotels Server | 2018-11-05 |