NA

CVE-2023-29839

Published: 03/05/2023 Updated: 09/05/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digitaldruid hotel druid 3.0.4

Vendor Advisories

Debian Bug report logs - #1035671 hoteldruid: CVE-2023-29839 Package: src:hoteldruid; Maintainer for src:hoteldruid is Marco Maria Francesco De Santis <marco@digitaldruidnet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 7 May 2023 15:33:02 UTC Severity: important Tags: security, upstream Found ...

Github Repositories

Hotel Druid 3.0.4 Stored Cross Site Scripting Vulnerability

CVE-2023-29839 Hotel Druid 304 Stored Cross Site Scripting Vulnerability CMS Link: wwwhoteldruidcom/ Version Affected: 304 Severity & CVSS: 54 (Medium) | Vector: CVSS:31/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages in Version 304 of the Hotel Druid application that allows for arbitrary e