CVE-2025-25749

HIGH

HotelDruid <3.0.7 - Info Disclosure

Title source: llm

Description

An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.

Exploits (1)

nomisec WRITEUP
by huyvo2910 · poc
https://github.com/huyvo2910/CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7

Scores

CVSS v3 7.1
EPSS 0.0133
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-521
Status published
Products (1)
digitaldruid/hoteldruid < 3.0.7
Published Mar 11, 2025
Tracked Since Feb 18, 2026