PT-2026-71371 · Unknown · Meeting Room Booking System
CVE-2026-46688
·
Published
2026-08-12
·
Updated
2026-08-13
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Meeting Room Booking System versions prior to 1.12.2
Description
Meeting Room Booking System is a PHP-based application for booking meeting rooms. An unauthenticated request can be made to redirect users to a location specified in the query. This allows an attacker to create a specially-crafted URL that redirects the user to an external site, such as a spoofed login page.
Recommendations
Update to version 1.12.2.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meeting Room Booking System