Executive brief
HotelRunner B2B, a platform used for business-to-business travel and hospitality management, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can send them to a fraudulent site that looks legitimate, potentially leading to credential theft or phishing attacks. This vulnerability undermines user trust and can be used as a starting point for more complex social engineering campaigns.
Technical details
An open redirect vulnerability (CWE-601) exists in HotelRunner B2B due to insufficient validation of user-supplied input used in redirection targets. A remote, unauthenticated attacker can exploit this by crafting a URL that, when visited by a legitimate user, redirects them to an arbitrary external domain. This flaw also facilitates 'forceful browsing' techniques. The vulnerability requires minimal user interaction (clicking a link) and is rated with a CVSS score of 4.7. A fix was implemented in the version released on or after June 4, 2025.
Affected products
- HotelRunner B2B before 04.06.2025
Timeline
- 2025-07-23: disclosed
- 2025-07-23: advisory
- 2025-06-04: patched