CVE-2025-44203

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:digitaldruid:hoteldruid:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:digitaldruid:hoteldruid:3.0.7:*:*:*:*:*:*:*

History

09 Jul 2026, 15:16

Type Values Removed Values Added
Summary (en) In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials. (en) In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.

26 Jun 2025, 14:35

Type Values Removed Values Added
CWE CWE-209
CWE-400
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Digitaldruid
Digitaldruid hoteldruid
CPE cpe:2.3:a:digitaldruid:hoteldruid:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:digitaldruid:hoteldruid:3.0.0:*:*:*:*:*:*:*
Summary
  • (es) En HotelDruid 3.0.7, un atacante no autenticado puede explotar mensajes de error SQL detallados en creadb.php antes de pulsar el botón "Crear base de datos". Al enviar solicitudes POST mal formadas a este endpoint, el atacante puede obtener el nombre de usuario, el hash de la contraseña y la sal del administrador. En algunos casos, el ataque resulta en una denegación de servicio (DoS), impidiendo que el administrador inicie sesión incluso con las credenciales correctas.
References () https://github.com/IvanT7D3/CVE-2025-44203/tree/main - () https://github.com/IvanT7D3/CVE-2025-44203/tree/main - Third Party Advisory
References () https://www.hoteldruid.com/ - () https://www.hoteldruid.com/ - Product

24 Jun 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/IvanT7D3/CVE-2025-44203/tree/main - () https://github.com/IvanT7D3/CVE-2025-44203/tree/main -
Summary
  • (es) En HotelDruid 3.0.7, un atacante no autenticado puede explotar mensajes de error SQL detallados en creadb.php antes de pulsar el botón "Crear base de datos". Al enviar solicitudes POST mal formadas a este endpoint, el atacante puede obtener el nombre de usuario, el hash de la contraseña y la sal del administrador. En algunos casos, el ataque resulta en una denegación de servicio (DoS), impidiendo que el administrador inicie sesión incluso con las credenciales correctas.
CWE CWE-209
CWE-400

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) En HotelDruid 3.0.7, un atacante no autenticado puede explotar mensajes de error SQL detallados en creadb.php antes de pulsar el botón "Crear base de datos". Al enviar solicitudes POST mal formadas a este endpoint, el atacante puede obtener el nombre de usuario, el hash de la contraseña y la sal del administrador. En algunos casos, el ataque resulta en una denegación de servicio (DoS), impidiendo que el administrador inicie sesión incluso con las credenciales correctas.

20 Jun 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) En HotelDruid 3.0.7, un atacante no autenticado puede explotar mensajes de error SQL detallados en creadb.php antes de pulsar el botón "Crear base de datos". Al enviar solicitudes POST mal formadas a este endpoint, el atacante puede obtener el nombre de usuario, el hash de la contraseña y la sal del administrador. En algunos casos, el ataque resulta en una denegación de servicio (DoS), impidiendo que el administrador inicie sesión incluso con las credenciales correctas.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
References () https://github.com/IvanT7D3/CVE-2025-44203/tree/main - () https://github.com/IvanT7D3/CVE-2025-44203/tree/main -
New CVE
CWE CWE-209
CWE-400
Summary
  • (es) En HotelDruid 3.0.7, un atacante no autenticado puede explotar mensajes de error SQL detallados en creadb.php antes de pulsar el botón "Crear base de datos". Al enviar solicitudes POST mal formadas a este endpoint, el atacante puede obtener el nombre de usuario, el hash de la contraseña y la sal del administrador. En algunos casos, el ataque resulta en una denegación de servicio (DoS), impidiendo que el administrador inicie sesión incluso con las credenciales correctas.

Information

Published : 2025-06-20 16:15

Updated : 2026-07-09 15:16


NVD link : CVE-2025-44203

Mitre link : CVE-2025-44203

CVE.ORG link : CVE-2025-44203


JSON object : View

Products Affected

digitaldruid

  • hoteldruid
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-400

Uncontrolled Resource Consumption