Record summary

CVE-2023-34537 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 3, 2025 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubleekenghwa/CVE-2023-34537---XSS-reflected--found-in-HotelDruid-3.0.5Repository PoCby leekenghwaStars: 0Not analyzed1 file

3.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMHoteldruid 3.0.5 - Cross-Site ScriptingCVSS 5.4

A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsHarsh
Template tagscve2023cvehoteldruixssauthenticateddigitaldruidvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:digitaldruid:hoteldruid:3.0.5:*:*:*:*:*:*:*
Shodan: http.title:"hoteldruid"
Shodan: http.favicon.hash:-1521640213
FOFA: title="hoteldruid"
FOFA: icon_hash=-1521640213
Google: intitle:"hoteldruid"

Source: ProjectDiscovery

References

2