CVE-2021-37832
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
- Affected products
- Debian, Hoteldruid, Sqlite
- Digitaldruid Hoteldruid
- = 3.0.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 4.1% (90th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-08-03
CVE-2021-37832 at NVD
4 known exploits for CVE-2021-37832
Proof-of-concept code and exploit modules indexed by Sploitus