Host Header Injection in HotelRunner’s B2B

CVE Details

Basic Information

Title Host Header Injection in HotelRunner’s B2B
Type cve
Published 2025-07-22T13:58:00.772Z
Modified 2025-07-22T14:08:09.870Z

Product Information

Vendor HotelRunner
Product B2B
Version 0

CVSS Information

Base Score 4.6 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Analysis

AI Description A vulnerability in HotelRunner’s B2B platform allows HTTP response splitting due to improper validation of certificates with host mismatches. This could enable attackers to manipulate server responses.
AI Severity Medium
AI Vendor HotelRunner
AI Product HotelRunner B2B
AI Version versions before 04.06.2025

Affected Products

  • HotelRunner B2B 0

Additional Information

CWE List CWE-297
Source TR-CERT

Description

Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. This issue affects B2B: before 04.06.2025.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.