In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
History

Thu, 26 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Digitaldruid
Digitaldruid hoteldruid
CPEs cpe:2.3:a:digitaldruid:hoteldruid:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:digitaldruid:hoteldruid:3.0.7:*:*:*:*:*:*:*
Vendors & Products Digitaldruid
Digitaldruid hoteldruid

Tue, 24 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-209
CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:45:00 +0000

Type Values Removed Values Added
Description In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-06-20T00:00:00.000Z

Updated: 2025-06-24T15:30:45.640Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-44203

cve-icon Vulnrichment

Updated: 2025-06-24T13:49:12.248Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-20T16:15:28.700

Modified: 2025-06-26T14:35:57.863

Link: CVE-2025-44203

cve-icon Redhat

No data.