4
CVSSv2

CVE-2019-9084

Published: 07/06/2019 Updated: 11/06/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

In Hoteldruid prior to 2.3.1, a division by zero exists in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service (disrupting certain business functions of the product).

Affected Products

Vendor Product Versions
HoteldruidHoteldruid1.3.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.3