Launchpad.net

CVE 2021-42949

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

See the CVE page on Mitre.org for more details.