📦 Hoteldruid

by Digitaldruid

🔍 What is Hoteldruid?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-43374

CRITICAL CVSS 9.8 Sep 20, 2023

This SQL injection vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary SQL commands via the id_utente_log parameter in the personalizza.php endpoint. This affects all systems runn...

CVE-2023-43371

CRITICAL CVSS 9.8 Sep 20, 2023

CVE-2023-43371 is a critical SQL injection vulnerability in Hoteldruid v3.0.5 that allows attackers to execute arbitrary SQL commands via the numcaselle parameter in the creaprezzi.php endpoint. This ...

CVE-2021-37832

CRITICAL CVSS 9.8 Aug 3, 2021

CVE-2021-37832 is a critical SQL injection vulnerability in Hotel Druid 3.0.2 when using SQLite database. Attackers can execute arbitrary SQL commands through the idappartamenti parameter, potentially...

CVE-2025-44203

HIGH CVSS 7.5 Jun 20, 2025

An unauthenticated attacker can exploit verbose SQL error messages in HotelDruid 3.0.7 to extract administrator credentials (username, password hash, and salt) via malformed POST requests to creadb.ph...

CVE-2022-22909

HIGH CVSS 8.8 Mar 3, 2022

HotelDruid v3.0.3 contains a remote code execution vulnerability where attackers can inject malicious payloads into the 'name' field when creating new rooms. This allows arbitrary code execution on th...

CVE-2025-55816

MEDIUM CVSS 6.1 Dec 11, 2025

HotelDruid v3.0.7 and earlier contains a cross-site scripting (XSS) vulnerability in the /modifica_app.php file. This allows attackers to inject malicious scripts that execute in users' browsers when ...