CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
83.6%
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability
via the id_utente_log parameter at /hoteldruid/personalizza.php.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | hoteldruid | < any | UNKNOWN |
ubuntu | 20.04 | noarch | hoteldruid | < any | UNKNOWN |
ubuntu | 22.04 | noarch | hoteldruid | < any | UNKNOWN |
ubuntu | 24.04 | noarch | hoteldruid | < any | UNKNOWN |
ubuntu | 16.04 | noarch | hoteldruid | < any | UNKNOWN |
flashy-lemonade-192.notion.site/SQL-injection-in-hoteldruid-version-3-0-5-via-id_utente_log-parameter-8b89f014004947e7bd2ecdacf1610cf9?pvs=4
launchpad.net/bugs/cve/CVE-2023-43374
nvd.nist.gov/vuln/detail/CVE-2023-43374
security-tracker.debian.org/tracker/CVE-2023-43374
www.cve.org/CVERecord?id=CVE-2023-43374