Unauthenticated Access to Valid Hotel Room Entries in Administrator Section
CVE-2024-42772
7.5HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 22 August 2024
What is CVE-2024-42772?
An issue was identified in the Kashipara Hotel Management System v1.0 that permits unauthorized users to access and view sensitive hotel room entries through the /admin/rooms.php page. This vulnerability arises from inadequate access control mechanisms, allowing unauthenticated attackers to exploit the system and compromise the integrity of private information. Organizations using this affected version should take immediate steps to rectify this security flaw to safeguard user data and maintain operational security.
