Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2021-42949
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.
0
Attacker Value
Unknown
CVE-2022-26564
Disclosure Date: April 26, 2022 (last updated October 07, 2023)
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
0
Attacker Value
Unknown
CVE-2022-22909
Disclosure Date: March 03, 2022 (last updated October 07, 2023)
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
0