CVE-2025-44203
CVE-2025-44203 is a high-severity vulnerability in Digitaldruid Hoteldruid with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-209.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-18763
- Weakness: CWE-209
- Affected product: Digitaldruid Hoteldruid
- Published:
- Last modified:
Description
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.
Frequently asked questions
- What is CVE-2025-44203?
- In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.
- How severe is CVE-2025-44203?
- CVE-2025-44203 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2025-44203 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-44203?
- CVE-2025-44203 primarily affects Digitaldruid Hoteldruid. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-44203?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-44203 have an EU (EUVD) identifier?
- Yes. CVE-2025-44203 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-18763.
- When was CVE-2025-44203 published?
- CVE-2025-44203 was published on 2025-06-20 and last updated on 2026-07-09.
References
Affected products (2)
- cpe:2.3:a:digitaldruid:hoteldruid:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:digitaldruid:hoteldruid:3.0.7:*:*:*:*:*:*:*
More vulnerabilities in Digitaldruid Hoteldruid
- CVE-2023-43375 — Critical (CVSS 9.8): Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the…
- CVE-2023-43374 — Critical (CVSS 9.8): Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at…
- CVE-2023-43373 — Critical (CVSS 9.8): Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at…
- CVE-2023-43371 — Critical (CVSS 9.8): Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at…
- CVE-2021-42949 — Critical (CVSS 9.8): The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session…
- CVE-2021-37832 — Critical (CVSS 9.8): A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application…
All CVEs affecting Digitaldruid Hoteldruid →
Other CWE-209 (Generation of Error Message Containing Sensitive Information) vulnerabilities
- CVE-2025-62168 — Critical (CVSS 10.0): Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication…
- CVE-2025-68110 — Critical (CVSS 9.9): ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an…
- CVE-2025-46658 — Critical (CVSS 9.8): An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.
- CVE-2024-28285 — Critical (CVSS 9.8): A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows…
- CVE-2023-40767 — Critical (CVSS 9.8): User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where…
- CVE-2023-40766 — Critical (CVSS 9.8): User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery,…
Browse all CWE-209 (Generation of Error Message Containing Sensitive Information) vulnerabilities →