RSSAmplifier

TrebledJ's Pages · Feb 13, 2026

When Hospitality Software is Too Hospitable (CVE-2026-21966, CVE-2026-21967)

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

Last autumn, as a typhoon hammered against the hotel windows, I found myself locked into a different kind of storm— a pentest that refused to stay routine. What began as a run-of-the-mill exercise quickly spiralled into yet another thrilling adventure of vulnerability disclosure. This writeup walks through my discovery of a Cross-Site Scripting (XSS) sanitization bypass and a powerful Server-Side…

Read on trebledj.me

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.