Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2021-38559

Disclosure Date: August 26, 2021 (last updated February 23, 2025)
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Attacker Value
Unknown

CVE-2021-37832

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
Attacker Value
Unknown

CVE-2021-37833

Disclosure Date: August 03, 2021 (last updated February 23, 2025)
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.