PT-2024-19667 · Unknown+1 · Hoteldruid+1

Published

2024-07-30

·

Updated

2024-08-23

·

CVE-2024-23091

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HotelDruid versions prior to 1.32
Description The issue is related to weak password hashing using MD5 in the funzioni.php file. This weakness allows an attacker to obtain plaintext passwords from hash values.
Recommendations For HotelDruid versions prior to 1.32, update to version 1.32 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23091

Affected Products

Debian
Hoteldruid