VYPR
Medium severity5.3NVD Advisory· Published May 13, 2022· Updated Jun 17, 2026

CVE-2022-27247

CVE-2022-27247

Description

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.

Affected products

3
  • cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*
  • cdSoft/Onlinetools-Smart Winhotel.MXdescription
  • Cdsoft/Cdsoftllm-fuzzy
    Range: 2021

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.