Division by Zero Vulnerability in Hoteldruid Application
CVE-2019-9084

4.9MEDIUM

Key Information:

Vendor
CVE Published:
7 June 2019

What is CVE-2019-9084?

In versions prior to 2.3.1 of Hoteldruid, a critical issue arises from a division by zero in the $num_tabelle variable located in the tab_tariffe.php file. This security gap is triggered by the mishandling of non-numeric inputs, which can lead to an unexpected behavior when an administrator uses certain parameters. For instance, accessing /tab_tariffe.php with malformed data could allow the execution of a denial of service attack, affecting the operation of the application and potentially disrupting key business functionalities.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.