VYPR

HotelDruid

by DigitalDruid

CVEs (30)

  • CVE-2022-26564MedApr 26, 2022
    risk 0.40cvss 6.1epss 0.03

    HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.

  • CVE-2021-38559MedAug 26, 2021
    risk 0.40cvss 6.1epss 0.01

    DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.

  • CVE-2021-37833MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.05

    A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

  • CVE-2025-25747MedMar 11, 2025
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

  • CVE-2023-43377MedSep 20, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.

  • CVE-2023-43376MedSep 20, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

  • CVE-2023-34537MedJun 13, 2023
    risk 0.35cvss 5.4epss 0.01

    A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

  • CVE-2023-29839MedMay 3, 2023
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

  • CVE-2019-9084MedJun 7, 2019
    risk 0.32cvss 4.9epss 0.02

    In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator…

  • CVE-2021-42948LowSep 16, 2022
    risk 0.24cvss 3.7epss 0.01

    HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.

Page 2 of 2