CVE Watchtower

← Back to CVE List

CVE-2023-34854NVD

Description

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
Severity Level
MEDIUM (6.6)
Published Date
14/09/2026
Last Modified
14/09/2026
Exploitation Status
????
EPSS Score
0.23% (percentile 13.8%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-434 - CWE-434 Unrestricted Upload of File with Dangerous Type

Affected & Patched Versions

ProductAffected VersionsPatched Version
digitaldruid HotelDruid0 - < 3.0.6N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.