HotelDruid XSS

MEDIUM (6.1) No Patch (2 days)

Threat Intelligence

High Risk - Exploits exist
EPSS Score: 0.03% chance of exploitation (percentile: 8%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: GitHub PoC

How we test →

What is it?

HotelDruid is an enterprise HR management system used by some organizations. This vulnerability allows attackers to inject malicious scripts into the application's /modifica_app.php file, potentially leading to unauthorized access and data theft.

Am I affected?

Specific version info not stated in the advisory. If you don't recognise this software, you're probably not affected.

Affected Products

aEnrich / HotelDruid

How to fix

  1. Upgrade to HotelDruid v3.0.8 or later from the official website: https://www.hoteldruid.com/en/download.html.
  2. If an immediate upgrade isn't possible, apply the following mitigations:
    • Restrict network access to your HotelDruid instance (firewall it from the public internet).
    • Audit admin account activity for suspicious access patterns.
    • Monitor for unauthorized token creation.