CVE-2024-42775

An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:jayesh:hotel_management_system:1.0:*:*:*:*:*:*:*

History

30 Apr 2025, 16:50

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Jayesh hotel Management System
Jayesh
CPE cpe:2.3:a:jayesh:hotel_management_system:1.0:*:*:*:*:*:*:*
References () https://www.kashipara.com/ - () https://www.kashipara.com/ - Product
References () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Hotel%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Add%20New%20Room%20Entry.pdf - () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Hotel%20Management%20System%20v1.0/Broken%20Access%20Control%20-%20Add%20New%20Room%20Entry.pdf - Exploit, Third Party Advisory

22 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-22 17:15

Updated : 2025-04-30 16:50


NVD link : CVE-2024-42775

Mitre link : CVE-2024-42775


JSON object : View

Products Affected

jayesh

  • hotel_management_system