CVE-2025-25747
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-25747 is a Cross-Site Scripting (XSS) vulnerability affecting DigitalDruid HotelDruid version 3.0.7. An attacker can exploit this issue by injecting malicious code into the ripristina_backup parameter of the crea_backup.php endpoint. Successful exploitation allows the attacker to execute arbitrary code and potentially obtain sensitive information from affected users. This vulnerability poses a significant risk, as XSS attacks can lead to data theft, account takeover, and other types of security breaches. It is recommended that users upgrade to the latest version of HotelDruid to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.