CVE-2025-25747

MEDIUM

HotelDruid 3.0.7 - Cross-Site Scripting via ripristina_backup Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-25747. PoCs published by huyvo2910.

AI-analyzed exploit summary This repository contains a working proof-of-concept for a reflected XSS vulnerability in HotelDruid 3.0.7 via the `ripristina_backup` parameter in `crea_backup.php`. The PoC demonstrates alert injection and external redirection.

Description

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

Exploits (1)

nomisec WORKING POC
by huyvo2910 · poc
https://github.com/huyvo2910/CVE-2025-25747-HotelDruid-3-0-7-Reflected-XSS

This repository contains a working proof-of-concept for a reflected XSS vulnerability in HotelDruid 3.0.7 via the `ripristina_backup` parameter in `crea_backup.php`. The PoC demonstrates alert injection and external redirection.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: HotelDruid 3.0.7
Auth required
Prerequisites: Valid authenticated session ID
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 5.4
EPSS 0.0049
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
digitaldruid/hoteldruid 3.0.7
Published Mar 11, 2025
Tracked Since Feb 18, 2026