Denial of Service in Hoteldruid by Affected Remote Users
CVE-2019-9085

6.5MEDIUM

Key Information:

Vendor
CVE Published:
24 June 2019

What is CVE-2019-9085?

The vulnerability allows remote authenticated users of Hoteldruid versions prior to 2.3.1 to trigger a denial of service by supplying invalid arguments to the n_file parameter in the visualizza_contratto.php file. This exploitation can cause invoice creation outages, impacting the availability and functionality of the service.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.