CVE-2023-29839: Digitaldruid Hoteldruid
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
Affected products
- Digitaldruid Hoteldruid: version 3.0.4 only
Published 2023-05-03. Last modified 2026-06-17.