In HotelDruid 3.0.7, an unauthenticated attacker can...
High severity
Unreviewed
Published
Jun 20, 2025
to the GitHub Advisory Database
•
Updated Jun 26, 2025
Description
Published by the National Vulnerability Database
Jun 20, 2025
Published to the GitHub Advisory Database
Jun 20, 2025
Last updated
Jun 26, 2025
In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
References