CVE-2023-34537
Hoteldruid 3.0.5 - Cross-Site Scripting
Record summary
CVE-2023-34537 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
Exploitation context
Proofs of concept
1Repository PoCs
GitHubleekenghwa/CVE-2023-34537---XSS-reflected--found-in-HotelDruid-3.0.5Repository PoCby leekenghwaStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMHoteldruid 3.0.5 - Cross-Site ScriptingCVSS 5.4
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery