Code Injection in HotelDruid - CVE-2022-22909
Published: February 22, 2022 / Updated: May 13, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the visualizza_tabelle.php and selectappartamenti.php scripts. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2022-22909
Links to Public Exploits and PoC-codes
- Exploit #7810 - Hotel Druid 3.0.3 - Remote Code Execution (RCE) (May 13, 2022)
- Exploit #7500 - CVE-2022-22909 ( Exploits for Hotel Druid 3.0.3 - Remote Code Execution (RCE) CVE-2022-22909) (March 15, 2022)
- Exploit #7382 - CVE-2022-22909 (Hotel Druid 3.0.3 Code Injection to Remote Code Execution) (February 23, 2022)