Security Advisory

CVE-2021-37832

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-08-03 12:30:57
Last updated 2024-08-04 01:30:08
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.