CVE-2023-29839
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
- Affected products
- Debian, Hoteldruid
- Digitaldruid Hoteldruid
- = 3.0.4
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.7% (49th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2023-05-03
CVE-2023-29839 at NVD
1 known exploit for CVE-2023-29839
Proof-of-concept code and exploit modules indexed by Sploitus