CVE-2021-37833
MEDIUM NUCLEIHotelDruid 3.0.2 - Reflected Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-37833. PoCs published by dievus. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository provides functional proof-of-concept payloads for a reflected XSS vulnerability in Hotel Druid 3.0.2. It includes specific URLs and parameters that can be manipulated to execute arbitrary JavaScript code.
Description
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
Exploits (1)
The repository provides functional proof-of-concept payloads for a reflected XSS vulnerability in Hotel Druid 3.0.2. It includes specific URLs and parameters that can be manipulated to execute arbitrary JavaScript code.
Nuclei Templates (1)
http.title:"hoteldruid" || http.favicon.hash:-1521640213
title="hoteldruid" || icon_hash=-1521640213
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N