CVE-2023-29839
Last modified
CVE-2023-29839 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Digitaldruid | Hoteldruid | 3.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-29839?
How severe is CVE-2023-29839?
How do I fix CVE-2023-29839?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-29827ejs v3.1.9 is vulnerable to server-side template injection. …9.8
- CVE-2023-2983Privilege Defined With Unsafe Actions in GitHub repository p…8.8
- CVE-2023-29835Insecure Permission vulnerability found in Wondershare Dr.Fo…7.8
- CVE-2023-29836Cross Site Scripting vulnerability found in Exelysis Unified…6.1
- CVE-2023-29837Cross Site Scripting vulnerability found in Exelysis Unified…6.1
- CVE-2023-29838Insecure Permission vulnerability found in Botkind/Siber Sys…7.8
- CVE-2023-2984Path Traversal: '\..\filename' in GitHub repository pimcore/…8.8
- CVE-2023-29842ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable t…8.8
- CVE-2023-29845Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2023-29847AeroCMS v0.0.1 was discovered to contain multiple stored cro…5.4
- CVE-2023-29848Bang Resto 1.0 was discovered to contain a stored cross-site…4.8
- CVE-2023-29849Bang Resto 1.0 was discovered to contain multiple SQL inject…8.8
Are you affected by CVE-2023-29839?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
