TrebledJ's Pages · Feb 13, 2026
When Hospitality Software is Too Hospitable (CVE-2026-21966, CVE-2026-21967)
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Last autumn, as a typhoon hammered against the hotel windows, I found myself locked into a different kind of storm— a pentest that refused to stay routine. What began as a run-of-the-mill exercise quickly spiralled into yet another thrilling adventure of vulnerability disclosure. This writeup walks through my discovery of a Cross-Site Scripting (XSS) sanitization bypass and a powerful Server-Side…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.