Impact
The vulnerability lies in an unspecified function within the /api/health/detailed endpoint of the Health Check component. By manipulating this endpoint, an attacker can trigger an unintended disclosure of sensitive system information. Because the attack can be performed over the network without prior authentication and the exploit is publicly available, a threat actor can extract details that could aid further compromise. This weakness is a classic information disclosure flaw, exposing internal data to unauthenticated or improperly protected clients.
Affected Systems
The affected product is arnobt78 Hotel Booking Management System. Versioning follows a rolling release model, and the exact versions affected are not enumerated. The vulnerability was found in functionality prior to the commit f8922d0e0f6ac1cc761974c7616f44c2bbc04bea.
Risk and Exploitability
The severity is scored as 6.9 on the CVSS scale, indicating a moderate to high risk. The EPSS score of < 1% reflects a very low exploitation probability, and the vulnerability is publicly documented and does not appear in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, and exploitation requires only that the actor can send a request to the /api/health/detailed endpoint, which may be unauthenticated or protected by weak access controls.
OpenCVE Enrichment