Cross-Site Request Forgery Vulnerability in Oganro Travel Portal Search Widget by Oganro
CVE-2025-49966

4.3MEDIUM

What is CVE-2025-49966?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Oganro Travel Portal Search Widget for the HotelBeds APITUDE API. This vulnerability can allow attackers to exploit the application by tricking authenticated users into submitting unwanted actions without their consent. The issue is present in versions from n/a up to and including 1.0, posing a threat to the integrity of user interactions with the platform.

Affected Version(s)

Oganro Travel Portal Search Widget for HotelBeds APITUDE API <= 1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chu The Anh (Blue Rock) (Patchstack Alliance)
.
CVE-2025-49966 : Cross-Site Request Forgery Vulnerability in Oganro Travel Portal Search Widget by Oganro