• Sign in
  • Register

Lost your password?

A password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.

Close
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
Cyber Threat

Critical OAuth Flaw Leaves Millions of Airline Travelers Vulnerable to Account Theft

ClickControl

Author

January 28, 2025

Published


Travel Service Vulnerability Exposed: Millions of Airline Users at Risk

A significant security flaw in a widely-used online travel service for hotel and car rentals has been discovered and patched, according to cybersecurity researchers at Salt Labs. The vulnerability potentially affected millions of users across multiple commercial airline platforms.

The security flaw allowed attackers to gain unauthorized access to user accounts through a sophisticated account takeover technique. Once compromised, attackers could:
– Book hotels and car rentals using victims’ airline loyalty points
– Modify or cancel existing bookings
– Access personal information
– Perform various account actions on behalf of the victim

The attack vector involved a simple yet effective method:
1. Creating a specially crafted link
2. Distributing it through common channels (email, SMS, websites)
3. Exploiting the OAuth authentication process between the rental service and airline platforms
4. Intercepting user session tokens by manipulating the “tr_returnUrl” parameter

The vulnerability was particularly concerning as it targeted the service-to-service API interactions, making it difficult to detect through standard security measures. The affected service, which remains unnamed, is integrated into numerous commercial airline online platforms and allows users to add hotel bookings to their airline itineraries.

The discovery highlights the critical importance of securing third-party integrations and API supply chain connections in travel service ecosystems. The vulnerability has since been addressed, protecting users from unauthorized access and account manipulation.

Keywords: travel security vulnerability, airline account security, OAuth authentication flaw, hotel booking security breach, loyalty points hack, API security travel

Share This Article
Tags: airline account security API security travel hotel booking security breach loyalty points hack OAuth authentication flaw travel security vulnerability
Previous Article Russian GRU Officers Face EU
Next Article Windows Audio Crisis Microsoft s
Curve Line
logo_white
Quick Links
  • Cybersecurity News
  • Video Guides
  • Shop
Company
  • Home
  • About us
  • Contact
  • Careers
  • Privacy Policy

(C) Copyright 2023-2026 ClickControl IT MSP & Cybersecurity, All Rights Reserved.