PT-2025-26429 · Unknown+1 · Hoteldruid+1

Ivant7D3

·

Published

2025-06-20

·

Updated

2025-07-01

·

CVE-2025-44203

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: HotelDruid version 3.0.7
Description: The issue allows an unauthenticated attacker to exploit verbose SQL error messages on the "creadb.php" endpoint before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
Recommendations: For HotelDruid version 3.0.7, as a temporary workaround, consider disabling the "creadb.php" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the username, password, and salt variables in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Generation of Error Message Containing Sensitive Information

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2025-44203

Affected Products

Debian
Hoteldruid