← Back to browse · API

CVE-2021-42949

Severity
CRITICAL
CVSS
9.8
EPSS
0.05833
Risk score
41.24
CISA KEV
No
PoC
No
Published
2022-09-16
Modified
2025-06-03
First seen
2026-08-07
Aliases
EUVD-2021-29904, GHSA-87G3-RX63-RRCH
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-29904

Description

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

References