Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hoteldruid vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2021-38559
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Digitaldruid Hoteldruid 3.0.2
384
VMScore
CVE-2022-26564
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
Digitaldruid Hoteldruid 3.0.3
NA
CVE-2023-34537
A Reflected XSS exists in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
Digitaldruid Hoteldruid 3.0.5
1 Github repository
NA
CVE-2023-43371
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43373
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43374
Hoteldruid v3.0.5 exists to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43375
Hoteldruid v3.0.5 exists to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43376
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-43377
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
Digitaldruid Hoteldruid 3.0.5
NA
CVE-2023-33817
hoteldruid v3.0.5 exists to contain a SQL injection vulnerability.
Digitaldruid Hoteldruid 3.0.5
1 Github repository
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »