Junglewise Threat Intelligence

CVE-2025-4296: HotelRunner B2B open redirect and forceful browsing

CVE-2025-4296 · Severity: medium · CVSS 4.7 · Published 2025-07-23

Technologies: HotelRunner B2B. Vendors: HotelRunner.

Executive brief

HotelRunner B2B, a platform used for business-to-business travel and hospitality management, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can send them to a fraudulent site that looks legitimate, potentially leading to credential theft or phishing attacks. This vulnerability undermines user trust and can be used as a starting point for more complex social engineering campaigns.

Technical details

An open redirect vulnerability (CWE-601) exists in HotelRunner B2B due to insufficient validation of user-supplied input used in redirection targets. A remote, unauthenticated attacker can exploit this by crafting a URL that, when visited by a legitimate user, redirects them to an arbitrary external domain. This flaw also facilitates 'forceful browsing' techniques. The vulnerability requires minimal user interaction (clicking a link) and is rated with a CVSS score of 4.7. A fix was implemented in the version released on or after June 4, 2025.

Affected products

  • HotelRunner B2B before 04.06.2025

Timeline

  • 2025-07-23: disclosed
  • 2025-07-23: advisory
  • 2025-06-04: patched

References

Related threats