PT-2025-10459 · Unknown+1 · Hoteldruid+1

Huy Vo

·

Published

2025-03-07

·

Updated

2025-04-07

·

CVE-2025-25749

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: HotelDruid versions 3.0.7 and earlier
Description: The issue allows users to set weak passwords due to the lack of enforcement of password strength policies.
Recommendations: For HotelDruid versions 3.0.7 and earlier, consider implementing a custom password strength policy to enforce strong passwords until a patch is available. As a temporary workaround, restrict the ability of users to set weak passwords by configuring the system to require a minimum password length and complexity.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-25749

Affected Products

Debian
Hoteldruid