Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-29839

Опубликовано: 03 мая 2023
Источник: debian
EPSS Низкий

Описание

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hoteldruidfixed3.0.5-1package
hoteldruidno-dsabookwormpackage
hoteldruidno-dsabullseyepackage
hoteldruidno-dsabusterpackage

Примечания

  • https://github.com/jichngan/CVE-2023-29839

  • Fixed upstream in 3.0.5

EPSS

Процентиль: 58%
0.0037
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 3 года назад

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

CVSS3: 5.4
nvd
почти 3 года назад

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

CVSS3: 5.4
github
почти 3 года назад

A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.

EPSS

Процентиль: 58%
0.0037
Низкий