Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-25747

Опубликовано: 11 мар. 2025
Источник: debian
EPSS Низкий

Описание

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hoteldruidfixed3.0.8-1package
hoteldruidno-dsabookwormpackage
hoteldruidpostponedbullseyepackage

Примечания

  • https://www.huyvo.net/post/cve-2025-25747-reflected-xss-vulnerability-in-hoteldruid-3-0-7

EPSS

Процентиль: 37%
0.00154
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
11 месяцев назад

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

CVSS3: 5.4
nvd
11 месяцев назад

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

CVSS3: 5.4
github
11 месяцев назад

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

EPSS

Процентиль: 37%
0.00154
Низкий