Medium severity5.3NVD Advisory· Published May 13, 2022· Updated Jun 17, 2026
CVE-2022-27247
CVE-2022-27247
Description
onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.
Affected products
3- cpe:2.3:a:cdsoft:winhotel.mx:2021:*:*:*:*:*:*:*
- cdSoft/Onlinetools-Smart Winhotel.MXdescription
Patches
Vulnerability mechanics
References
2- myses.de/pdf/CVE2022-27247.pdfnvdExploitThird Party Advisory
- myses.denvdThird Party Advisory
News mentions
0No linked articles in our index yet.