Vulnerability Details CVE-2022-22909
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.331
EPSS Ranking 96.7%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2022-22909
-
cpe:2.3:a:digitaldruid:hoteldruid:3.0.3