Vulnerability record · CVE-2021-42949 · published 16 September 2022
CVE-2021-42949: Digitaldruid hoteldruid improper authentication vulnerability
Digitaldruid · Hoteldruid
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
Description
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/dhammon/HotelDruid-CVE-2021-42949 | Third Party Advisory |
| https://github.com/dhammon/Security | Broken Link |
| https://www.hoteldruid.com/ | ProductVendor Advisory |
| https://github.com/dhammon/HotelDruid-CVE-2021-42949 | Third Party Advisory |
| https://github.com/dhammon/Security | Broken Link |
| https://www.hoteldruid.com/ | ProductVendor Advisory |
Track CVE-2021-42949 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42949), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.