CVE-2023-29839

MEDIUM

Digitaldruid Hoteldruid - XSS

Title source: rule
STIX 2.1

Description

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

Exploits (1)

nomisec WRITEUP 1 stars
by jichngan · poc
https://github.com/jichngan/CVE-2023-29839

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0054
EPSS Percentile 67.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
digitaldruid/hoteldruid 3.0.4
Published May 03, 2023
Tracked Since Feb 18, 2026