CVE-2019-9085
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_contratto=1&n_file=a query string to visualizza_contratto.php.
Hoteldruid anterior a versión v2.3.1, permite a los usuarios autenticados remotos causar una denegación de servicio (corte de creación de factura) por medio del parámetro n_file en el archivo visualizza_contratto.php con argumentos no válidos (cualquier valor no numérico), como es demostrado por la cadena de consulta anno=2019&id_transazione=1&numero_contratto=1&n_file=a en visualizza_contratto.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-24 CVE Reserved
- 2019-06-24 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://metamorfosec.com/Files/Advisories/METS-2019-006-An_Invalid_Arguments_in_Hoteldruid_before_v2.3.1.txt | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.hoteldruid.com/en/download.html | 2019-06-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digitaldruid Search vendor "Digitaldruid" | Hoteldruid Search vendor "Digitaldruid" for product "Hoteldruid" | < 2.3.1 Search vendor "Digitaldruid" for product "Hoteldruid" and version " < 2.3.1" | - |
Affected
|