Cross-Site Request Forgery Vulnerability in HotelRunner Booking Widget by HotelRunner
CVE-2025-60168
7.1HIGH
What is CVE-2025-60168?
A Cross-Site Request Forgery vulnerability exists in HotelRunner Booking Widget, potentially allowing attackers to exploit the widget by triggering unauthorized actions on behalf of logged-in users. This flaw could lead to the execution of stored cross-site scripting attacks, jeopardizing the security of user data and interactions within the application.
Affected Version(s)
HotelRunner Booking Widget <= n/a