CVE-2023-34854

Summary

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

Affected Software

VendorProductVersion RangeStatus
digitaldruidHotelDruid0 < 3.0.6affected

Weaknesses

  • CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References