CVE-2019-7648: Hotels Server Project Hotels Server
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to protect password storage.
Affected products
- Hotels Server Project Hotels Server: up to and including 2018-11-05
Published 2019-02-08. Last modified 2026-06-17.