PT-2025-26429 · Unknown+1 · Hoteldruid+1
Ivant7D3
·
Published
2025-06-20
·
Updated
2025-07-01
·
CVE-2025-44203
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
HotelDruid version 3.0.7
Description:
The issue allows an unauthenticated attacker to exploit verbose SQL error messages on the "creadb.php" endpoint before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator
username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.Recommendations:
For HotelDruid version 3.0.7, as a temporary workaround, consider disabling the "creadb.php" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the
username, password, and salt variables in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Generation of Error Message Containing Sensitive Information
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Hoteldruid