CVE-2023-34854
Received Received - Intake

Insufficient File Upload Sanitation in HotelDruid

Vulnerability report for CVE-2023-34854, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hoteldruid hoteldruid to 3.0.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HotelDruid before version 3.0.6 has a vulnerability in the backup/restore function that allows insufficient file upload sanitation. This means an attacker with access could upload malicious files that may lead to remote code execution.

Detection Guidance

To detect this vulnerability, check the installed version of HotelDruid. If using Debian bookworm, versions before 3.0.8-1 are vulnerable. Run commands like 'dpkg -l | grep hoteldruid' to verify the version.

Impact Analysis

If exploited, this vulnerability could allow an authenticated attacker to execute arbitrary code on the server running HotelDruid. This could lead to unauthorized access, data theft, or further compromise of the system.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using vulnerable versions may face legal and financial penalties.

Mitigation Strategies

Upgrade HotelDruid to version 3.0.8-1 or later. If using Debian bookworm, install version 3.0.8-1 or newer. For Debian unstable (sid), ensure version 3.0.6-1 or higher is installed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-34854. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart