CVE-2025-4542
LOWFreeebird Hotel < 1.2 - Permissive CORS Policy
Title source: ruleDescription
A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统 API up to 1.2. Affected by this issue is some unknown functionality of the file /src/main/java/cn/mafangui/hotel/tool/SessionInterceptor.java. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
3.1
EPSS
0.0008
EPSS Percentile
24.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-942
CWE-346
Status
published
Affected Products (1)
freeebird/hotel
< 1.2
Timeline
Published
May 11, 2025
Tracked Since
Feb 18, 2026