CVE-2025-44203
Last modified
CVE-2025-44203 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Digitaldruid | Hoteldruid | 3.0.0 |
| Digitaldruid | Hoteldruid | 3.0.7 |
References
- https://github.com/IvanT7D3/CVE-2025-44203/tree/mainThird Party Advisory
- https://www.hoteldruid.com/Product
- https://github.com/IvanT7D3/CVE-2025-44203/tree/mainThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-44203?
How severe is CVE-2025-44203?
How do I fix CVE-2025-44203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4419The Hot Random Image plugin for WordPress is vulnerable to P…4.3
- CVE-2025-44192SourceCodester Simple Barangay Management System v1.0 has a …9.8
- CVE-2025-44193SourceCodester Simple Barangay Management System v1.0 has a …7.6
- CVE-2025-44194SourceCodester Simple Barangay Management System v1.0 has a …7.3
- CVE-2025-4420The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommer…6.4
- CVE-2025-44201Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2025-44206Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.002…4.6
- CVE-2025-4421The vulnerability was identified in the code developed speci…8.2
- CVE-2025-4422The vulnerability was identified in the code developed speci…8.2
- CVE-2025-4423The vulnerability was identified in the code developed speci…8.2
- CVE-2025-4424The vulnerability was identified in the code developed speci…6
- CVE-2025-4425The vulnerability was identified in the code developed speci…8.2
Are you affected by CVE-2025-44203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
