CVE-2025-25747
MEDIUMHotelDruid 3.0.7 - Cross-Site Scripting via ripristina_backup Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-25747. PoCs published by huyvo2910.
AI-analyzed exploit summary This repository contains a working proof-of-concept for a reflected XSS vulnerability in HotelDruid 3.0.7 via the `ripristina_backup` parameter in `crea_backup.php`. The PoC demonstrates alert injection and external redirection.
Description
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
Exploits (1)
This repository contains a working proof-of-concept for a reflected XSS vulnerability in HotelDruid 3.0.7 via the `ripristina_backup` parameter in `crea_backup.php`. The PoC demonstrates alert injection and external redirection.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N