github.com
https://github.com/0z09e/CVE-2022-22909 CVE-2022-22909
HIGH
Hotel Druid 3.0.3 - Remote Code Execution (RCE)
Record summary
CVE-2022-22909 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBHotel Druid 3.0.3 - Remote Code Execution (RCE)ExploitDB exploitby 0z09eNot analyzed1 file
Repository PoCs
GitHub0z09e/CVE-2022-22909Repository PoCby 0z09eStars: 5Not analyzed6 files
GitHubkaal18/CVE-2022-22909Repository PoCby kaal18Stars: 2Not analyzed3 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-22909 hoteldruid.com
https://www.hoteldruid.com/