Debian Hoteldruid vulnerabilities
30 known vulnerabilities affecting debian/hoteldruid.
Total CVEs
30
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH5MEDIUM13LOW2UNKNOWN2
Vulnerabilities
Page 2 of 2
CVE-2021-38559P4MEDIUMCVSS 6.1fixed in hoteldruid 3.0.3-1 (bookworm)2021
CVE-2021-38559 [MEDIUM] CVE-2021-38559: hoteldruid - DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting ...
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Scope: local
bookworm: resolved (fixed in 3.0.3-1)
bullseye: open
sid: resolved (fixed in 3.0.3-1)
debian
CVE-2025-55816P4MEDIUMCVSS 6.1fixed in hoteldruid 3.0.8-1 (sid)2025
CVE-2025-55816 [MEDIUM] CVE-2025-55816: hoteldruid - HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the ...
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.8-1)
debian
CVE-2023-29839P4MEDIUMCVSS 5.4fixed in hoteldruid 3.0.5-1 (sid)2023
CVE-2023-29839 [MEDIUM] CVE-2023-29839: hoteldruid - A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Ho...
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.5-1)
debian
CVE-2025-25747P4MEDIUMCVSS 5.4fixed in hoteldruid 3.0.8-1 (sid)2025
CVE-2025-25747 [MEDIUM] CVE-2025-25747: hoteldruid - Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an ...
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.8-1)
debian
CVE-2019-9084P4MEDIUMCVSS 4.9fixed in hoteldruid 2.3.2-1 (bookworm)2019
CVE-2019-9084 [MEDIUM] CVE-2019-9084: hoteldruid - In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in...
In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service (disrupting certain business functions of the prod
debian
CVE-2023-43377P4MEDIUMCVSS 5.4fixed in hoteldruid 3.0.6-1 (sid)2023
CVE-2023-43377 [MEDIUM] CVE-2023-43377: hoteldruid - A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.p...
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.6-1)
debian
CVE-2023-43376P4MEDIUMCVSS 5.4fixed in hoteldruid 3.0.6-1 (sid)2023
CVE-2023-43376 [MEDIUM] CVE-2023-43376: hoteldruid - A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldr...
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.6-1)
debian
CVE-2021-42948P4LOWCVSS 3.7fixed in hoteldruid 3.0.4-1 (bookworm)2021
CVE-2021-42948 [LOW] CVE-2021-42948: hoteldruid - HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exp...
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.
Scope: local
bookworm: resolved (fixed in 3.0.4-1)
bullseye: open
sid: resolved (fixed in 3.0.4-1)
debian
CVE-2023-34854UNKNOWNfixed in hoteldruid 3.0.6-1 (sid)2023
CVE-2023-34854 CVE-2023-34854: hoteldruid
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.6-1)
debian
CVE-2022-45592UNKNOWNfixed in hoteldruid 3.0.6-1 (sid)2022
CVE-2022-45592 CVE-2022-45592: hoteldruid
bookworm: open
bullseye: open
sid: resolved (fixed in 3.0.6-1)
debian
← Previous2 / 2