The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
{ "binaries": [ { "binary_version": "2.1.4-1ubuntu2", "binary_name": "hoteldruid" } ] }
{ "binaries": [ { "binary_version": "2.2.2-1", "binary_name": "hoteldruid" } ] }
{ "binaries": [ { "binary_version": "3.0.1-1", "binary_name": "hoteldruid" } ] }
{ "binaries": [ { "binary_version": "3.0.3-1", "binary_name": "hoteldruid" } ] }