mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
1.0 KiB
1.0 KiB
CVE-2025-25747
Description
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
POC
Reference
Github
- https://github.com/huyvo2910/CVE-2025-25747-HotelDruid-3-0-7-Reflected-XSS
- https://github.com/huyvo2910/CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7
- https://github.com/huyvo2910/Coordinated-Vulnerability-Disclosure---HotelDruid-3.0.7
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/plzheheplztrying/cve_monitor