CVE-2022-22909
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
- Affected products
- Debian, Hoteldruid
- Digitaldruid Hoteldruid
- = 3.0.3
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 45.4% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2022-03-02
CVE-2022-22909 at NVD
7 known exploits for CVE-2022-22909
Proof-of-concept code and exploit modules indexed by Sploitus