ZeroHour

CVE-2023-29839

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p50
Published
()
Modified
Description

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

Vendors
digitaldruid
Products
hoteldruid
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.