CVE-2025-25747

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 11, 2025
Updated: Mar 12, 2025
CWE ID 79

Summary

CVE-2025-25747 is a Cross-Site Scripting (XSS) vulnerability affecting DigitalDruid HotelDruid version 3.0.7. An attacker can exploit this issue by injecting malicious code into the ripristina_backup parameter of the crea_backup.php endpoint. Successful exploitation allows the attacker to execute arbitrary code and potentially obtain sensitive information from affected users. This vulnerability poses a significant risk, as XSS attacks can lead to data theft, account takeover, and other types of security breaches. It is recommended that users upgrade to the latest version of HotelDruid to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share