CVE-2025-44203
HIGHHotelDruid 3.0.7 - Unauthenticated Information Disclosure and Denial of Service via creadb.php SQL Error Messages
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-44203. PoCs published by IvanT7D3.
AI-analyzed exploit summary This PoC exploits CVE-2025-44203 in HotelDruid 3.0.0/3.0.7 by sending multiple POST requests to 'creadb.php' to trigger verbose SQL error messages, disclosing sensitive information (username, password hash, salt) and causing a DoS condition. The 'brute.py' script assists in cracking the recovered password hash using a wordlist.
Description
In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
Exploits (1)
This PoC exploits CVE-2025-44203 in HotelDruid 3.0.0/3.0.7 by sending multiple POST requests to 'creadb.php' to trigger verbose SQL error messages, disclosing sensitive information (username, password hash, salt) and causing a DoS condition. The 'brute.py' script assists in cracking the recovered password hash using a wordlist.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H