Vulnerability Description
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jayesh | Hotel Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Hotel%20ManagemenExploitThird Party Advisory
- https://www.kashipara.com/Product
FAQ
What is CVE-2024-42775?
CVE-2024-42775 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room en...
How severe is CVE-2024-42775?
CVE-2024-42775 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-42775?
Check the references section above for vendor advisories and patch information. Affected products include: Jayesh Hotel Management System.