Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-25748

Опубликовано: 11 мар. 2025
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:digitaldruid:hoteldruid:3.0.7:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00057
Низкий

7.3 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.3
ubuntu
11 месяцев назад

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.

CVSS3: 7.3
debian
11 месяцев назад

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid ...

CVSS3: 7.3
github
11 месяцев назад

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens.

EPSS

Процентиль: 18%
0.00057
Низкий

7.3 High

CVSS3

Дефекты

CWE-352