CVE-2021-37833
MEDIUM NUCLEIDigitaldruid Hoteldruid - XSS
Title source: ruleDescription
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
Exploits (1)
Nuclei Templates (1)
Hotel Druid 3.0.2 - Cross-Site Scripting
MEDIUMby pikpikcu,s4e-io
Shodan:
http.title:"hoteldruid" || http.favicon.hash:-1521640213
FOFA:
title="hoteldruid" || icon_hash=-1521640213
Scores
CVSS v3
6.1
EPSS
0.1157
EPSS Percentile
93.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
digitaldruid/hoteldruid
3.0.2
Published
Aug 03, 2021
Tracked Since
Feb 18, 2026