CVE-2019-8937
MEDIUM NUCLEIDigitaldruid Hoteldruid - XSS
Title source: ruleDescription
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
Exploits (1)
Nuclei Templates (1)
HotelDruid 2.3.0 - Cross-Site Scripting
MEDIUMVERIFIEDby LogicalHunter
Shodan:
http.title:"hoteldruid" || http.favicon.hash:-1521640213
FOFA:
title="hoteldruid" || icon_hash=-1521640213
References (3)
Scores
CVSS v3
6.1
EPSS
0.4377
EPSS Percentile
97.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
digitaldruid/hoteldruid
2.3.0
Published
May 17, 2019
Tracked Since
Feb 18, 2026