Cross Site Scripting Vulnerability in DigitalDruid HotelDruid Software
CVE-2025-25747
5.4MEDIUM
What is CVE-2025-25747?
A Cross Site Scripting (XSS) vulnerability in DigitalDruid's HotelDruid version 3.0.7 enables attackers to execute arbitrary code through the ripristina_backup parameter in the crea_backup.php endpoint. This exploitation could lead to unauthorized access and the potential leakage of sensitive information, compromising the security of applications reliant on this software.
