IvanT7D3

2 exploits Active since Jun 2025
CVE-2025-44203 NOMISEC HIGH WORKING POC
Digitaldruid Hoteldruid - Error Information Exposure
In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
CVSS 7.5
CVE-2025-44203 WRITEUP HIGH WORKING POC
Digitaldruid Hoteldruid - Error Information Exposure
In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
CVSS 7.5