XSS Vulnerability in DigitalDruid HotelDruid Software
CVE-2021-38559

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 August 2021

What is CVE-2021-38559?

DigitalDruid HotelDruid version 3.0.2 contains a Cross-Site Scripting (XSS) vulnerability in the prenota.php file, which affects the fineperiodo1 parameter. This flaw allows attackers to inject malicious scripts into web pages viewed by users. By exploiting this vulnerability, an attacker can potentially steal session cookies or perform actions on behalf of users, emphasizing the need for immediate attention to web application security in affected systems.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.