CVE-2019-7648: Hotels Server Project Hotels Server

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.

Affected products

Published 2019-02-08. Last modified 2026-06-17.