Critical severity9.8NVD Advisory· Published Sep 16, 2022· Updated Jun 17, 2026
CVE-2021-42949
CVE-2021-42949
Description
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:digitaldruid:hoteldruid:3.0.3:*:*:*:*:*:*:*
- HotelDruid/Hotel Management Softwaredescription
- Range: =3.0.3
Patches
Vulnerability mechanics
References
2- www.hoteldruid.comnvdProductVendor Advisory
- github.com/dhammon/SecuritynvdBroken Link
News mentions
0No linked articles in our index yet.