CVE-2025-44203

Source
https://cve.org/CVERecord?id=CVE-2025-44203
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-44203.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-44203
Downstream
Published
2025-06-20T16:15:28.700Z
Modified
2026-03-14T12:42:44.275138Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-44203.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "3.0.7"
            }
        ]
    }
]