PT-2025-50724 · Unknown+1 · Hoteldruid+1

CVE-2025-55816

·

Published

2025-12-11

·

Updated

2025-12-14

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HotelDruid versions prior to 3.0.8
Description HotelDruid versions 3.0.7 and earlier are susceptible to Cross Site Scripting (XSS). The issue is located in the /modifica app.php file. The vulnerability allows for the injection of malicious scripts through this file.
Recommendations Update HotelDruid to version 3.0.8 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55816

Affected Products

Debian
Hoteldruid