SQL Injection Vulnerabilities in Hoteldruid by Flashy Lemonade
CVE-2023-43375

9.8CRITICAL

Key Information:

Vendor
CVE Published:
20 September 2023

What is CVE-2023-43375?

Hoteldruid v3.0.5 has been found to exhibit multiple SQL injection vulnerabilities that can be exploited through various parameters in the /hoteldruid/clienti.php endpoint, specifically via annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc. These vulnerabilities can allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized data access or manipulation, thus compromising the integrity and confidentiality of the system.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.