Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
digitaldruid hoteldruid vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-47164
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and previous versions allows a remote unauthenticated malicious user to execute an arbitrary script on the web browser of the user who is logging in to the product.
Digitaldruid Hoteldruid
4.9
CVSSv3
CVE-2019-9084
In Hoteldruid prior to 2.3.1, a division by zero exists in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to ...
Digitaldruid Hoteldruid
6.5
CVSSv3
CVE-2019-9085
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_...
Digitaldruid Hoteldruid
3.7
CVSSv3
CVE-2021-42948
HotelDruid Hotel Management Software v3.0.3 and below exists to have exposed session tokens in multiple links via GET parameters, allowing malicious users to access user session id's.
Digitaldruid Hoteldruid
2 Github repositories
9.8
CVSSv3
CVE-2018-1000871
HotelDruid HotelDruid 2.3.0 version 2.3.0 and previous versions contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack appear to b...
Digitaldruid Hoteldruid
9.8
CVSSv3
CVE-2019-9086
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
Digitaldruid Hoteldruid
9.8
CVSSv3
CVE-2019-9087
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
Digitaldruid Hoteldruid
9.8
CVSSv3
CVE-2023-43373
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Digitaldruid Hoteldruid 3.0.5
5.4
CVSSv3
CVE-2023-43377
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
Digitaldruid Hoteldruid 3.0.5
6.1
CVSSv3
CVE-2021-38559
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Digitaldruid Hoteldruid 3.0.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »