SQL Injection Vulnerability in HotelDruid Software by HotelDruid
CVE-2019-9086
9.8CRITICAL
What is CVE-2019-9086?
The vulnerability allows attackers to exploit HotelDruid software versions prior to 2.3.1 through SQL Injection via the 'anno' parameter in the /visualizza_tabelle.php script. This can lead to unauthorized access to the underlying database, potentially exposing sensitive information. Users are advised to upgrade to the latest version to mitigate this risk.
