Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jichngan

#47140of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2023-22439
5.4
2023-05-03
Unknown · Hoteldruid · CVE-2023-29839
**Name of the Vulnerable Software and Affected Versions** Hotel Druid version 3.0.4 **Description** A Stored Cross Site Scripting (XSS) issue exists in multiple pages, allowing arbitrary execution of commands. The vulnerable fields are `Surname`, `Name`, and `Nickname` in the `Document` function. **Recommendations** For Hotel Druid version 3.0.4, consider disabling the `Document` function or restricting input for the `Surname`, `Name`, and `Nickname` fields until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.