A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/jichngan/CVE-2023-29839 |
![]() ![]() |
History
Mon, 07 Apr 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Digitaldruid hoteldruid
|
|
CPEs | cpe:2.3:a:digitaldruid:hoteldruid:3.0.4:*:*:*:*:*:*:* | |
Vendors & Products |
Digitaldruid hotel Druid
|
Digitaldruid hoteldruid
|
Thu, 30 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-30T17:14:26.992Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-29839

Updated: 2024-08-02T14:14:39.940Z

Status : Modified
Published: 2023-05-03T03:15:08.137
Modified: 2025-04-07T14:15:09.590
Link: CVE-2023-29839

No data.