Record summary

CVE-2022-26564 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMHotelDruid Hotel Management Software 3.0.3 - Cross-Site ScriptingCVSS 6.1

HotelDruid Hotel Management Software 3.0.3 contains a cross-site scripting vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a victim's browser, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
Authorsalexrydzak
Template tagscvecve2022hoteldruidxssdigitaldruidvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:digitaldruid:hoteldruid:3.0.3:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-1521640213
Shodan: http.title:"hoteldruid"
FOFA: title="hoteldruid"
FOFA: icon_hash=-1521640213
Google: intitle:"hoteldruid"

Source: ProjectDiscovery

References

3