Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
digitaldruid hoteldruid 3.0.5 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-33817
hoteldruid v3.0.5 exists to contain a SQL injection vulnerability.
Digitaldruid Hoteldruid 3.0.5
1 Github repository
5.4
CVSSv3
CVE-2023-34537
A Reflected XSS exists in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
Digitaldruid Hoteldruid 3.0.5
1 Github repository
9.8
CVSSv3
CVE-2023-43371
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
Digitaldruid Hoteldruid 3.0.5
9.8
CVSSv3
CVE-2023-43373
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Digitaldruid Hoteldruid 3.0.5
9.8
CVSSv3
CVE-2023-43374
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
Digitaldruid Hoteldruid 3.0.5
9.8
CVSSv3
CVE-2023-43375
Hoteldruid v3.0.5 exists to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.
Digitaldruid Hoteldruid 3.0.5
5.4
CVSSv3
CVE-2023-43376
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.
Digitaldruid Hoteldruid 3.0.5
5.4
CVSSv3
CVE-2023-43377
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
Digitaldruid Hoteldruid 3.0.5
6.1
CVSSv3
CVE-2023-47164
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and previous versions allows a remote unauthenticated malicious user to execute an arbitrary script on the web browser of the user who is logging in to the product.
Digitaldruid Hoteldruid
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
race condition
CVE-2024-4249
CVE-2024-4244
CVE-2023-20198
TCP
CVE-2022-48648
CVE-2022-48636
CVE-2024-21345
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started