CVE-2019-8937
MEDIUM NUCLEIHotelDruid 2.3.0 - Stored Cross-Site Scripting via nsextt, cambia1, mese_fine, origine, and anno Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-8937. PoCs published by Mehmet EMIROGLU. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Hoteldruid 2.3 via various parameters (nsextt, cambia1, mese_fine, origine, anno). The attack patterns use onmouseover events to trigger JavaScript alerts, confirming the presence of reflected XSS.
Description
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
Exploits (1)
This exploit demonstrates multiple XSS vulnerabilities in Hoteldruid 2.3 via various parameters (nsextt, cambia1, mese_fine, origine, anno). The attack patterns use onmouseover events to trigger JavaScript alerts, confirming the presence of reflected XSS.
Nuclei Templates (1)
http.title:"hoteldruid" || http.favicon.hash:-1521640213
title="hoteldruid" || icon_hash=-1521640213
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N