Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
digitaldruid hoteldruid vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-43373
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43374
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43375
Hoteldruid v3.0.5 exists to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43376
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43377
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2021-42949
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing malicious users to bypass authentication via bruteforce attacks.
Digitaldruid Hoteldruid 3.0.3
2 Github repositories
4.3
CVSSv2
CVE-2021-38559
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Digitaldruid Hoteldruid 3.0.2
7.5
CVSSv2
CVE-2021-37832
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
Digitaldruid Hoteldruid 3.0.2
2 Github repositories
4.3
CVSSv2
CVE-2021-37833
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
Digitaldruid Hoteldruid 3.0.2
1 Github repository
4.3
CVSSv2
CVE-2019-8937
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
Digitaldruid Hoteldruid 2.3.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »