Vulnerability Description
Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digitaldruid | Hoteldruid | 3.0.5 |
Related Weaknesses (CWE)
References
- https://flashy-lemonade-192.notion.site/Cross-site-scripting-in-hoteldruid-versiNot Applicable
- https://flashy-lemonade-192.notion.site/Cross-site-scripting-in-hoteldruid-versiNot Applicable
FAQ
What is CVE-2023-43375?
CVE-2023-43375 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, a...
How severe is CVE-2023-43375?
CVE-2023-43375 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-43375?
Check the references section above for vendor advisories and patch information. Affected products include: Digitaldruid Hoteldruid.