Vulnerabilities
Vulnerable Software
Digitaldruid:  >> Hoteldruid  Security Vulnerabilities
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-09-20
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-09-20
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
CVSS Score
8.8
EPSS Score
0.12
Published
2023-06-13
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
CVSS Score
5.4
EPSS Score
0.128
Published
2023-06-13
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-05-03
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
CVSS Score
3.7
EPSS Score
0.002
Published
2022-09-16
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
CVSS Score
9.8
EPSS Score
0.374
Published
2022-09-16
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
CVSS Score
6.1
EPSS Score
0.007
Published
2022-04-26
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
CVSS Score
8.8
EPSS Score
0.331
Published
2022-03-03
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-08-26


Contact Us

Shodan ® - All rights reserved