CVE-2022-27247

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.
References
Link Resource
https://myses.de/#about Third Party Advisory
https://myses.de/pdf/CVE2022-27247.pdf Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*

Information

Published : 2022-05-13 03:15

Updated : 2022-05-24 04:03


NVD link : CVE-2022-27247

Mitre link : CVE-2022-27247

Products Affected
No products.
CWE