Vulnerabilities > Digitaldruid > Hoteldruid
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-05-17 | CVE-2019-8937 | Cross-site Scripting vulnerability in Digitaldruid Hoteldruid 2.3.0 HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php. | 4.3 |
2018-12-20 | CVE-2018-1000871 | SQL Injection vulnerability in Digitaldruid Hoteldruid HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. | 7.5 |