VendorsDigitaldruidhoteldruid3.0.2
Vulnerabilities

Digitaldruid HotelDruid 3.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-37832
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
Published 2021-08-03 · Modified
9.8EPSS 0.041
CVE-2021-37833
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
Published 2021-08-03 · Modified
6.1EPSS 0.049
CVE-2021-38559
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Published 2021-08-26 · Modified
6.1EPSS 0.010