Stored Cross Site Scripting Vulnerability in Hotel Druid by Jichngan
CVE-2023-29839
5.4MEDIUM
Key Information:
- Vendor
Digitaldruid
- Status
- Vendor
- CVE Published:
- 3 May 2023
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2023-29839?
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, allowing adversaries to execute arbitrary commands by exploiting vulnerable input fields such as Surname, Name, and Nickname in the Document function. This vulnerability could potentially expose sensitive user data and compromise the integrity of the application.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
