CVE-2019-8937: Digitaldruid Hoteldruid

Medium severity, CVSS 6.1. EPSS: 10.6% chance of exploitation in the next 30 days.

HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.

Affected products

Published 2019-05-17. Last modified 2026-06-17.