← Back

CVE-2025-44203

nvd nist
Published: Jun 20, 2025Modified: Jun 26, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

Affected (2)

1 product
Hoteldruid
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Digitaldruid
Version 3.0.0
Version 3.0.7

References (3)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Product
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory

Timeline

No history available yet.