Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the nfile parameter to visualizzacontratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&idtransazione=1&numerocontratto=1&nfile=a query string to visualizzacontratto.php.