Description
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
Published: 2026-09-14
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote file upload via backup/restore feature could place arbitrary files on the system
Action: Update immediately
AI Analysis

Impact

HotelDruid versions before 3.0.6 use inadequate validation when files are uploaded during backup and restore operations. This flaw permits uploading of arbitrary files to the server impact can range from accidental exposure of data to execution of malicious code if the uploaded file is later processed by privileged components. The description does not specify that it leads directly to arbitrary code execution, but it poses a risk of improper file placement and subsequent exploitation if those files are executed or parsed. Based on the description, it is inferred that the backup/restore functionality is exposed over HTTP or HTTPS.

Affected Systems

Any deployment of HotelDruid prior to version 3.0.6 is affected. This includes all installations of the digitaldruid:HotelDruid application identified by the vendor and product names in the CNA data. No specific subsystem or operating system is singled out, so the vulnerability applies broadly to all affected host environments where the backup/restore endpoint is reachable.

Risk and Exploitability

The CVSS score is 6.6, indicating that while exploitation is considered feasible, it requires that the attacker can reach the function and successfully upload a file. The EPSS score is < 1%, meaning the probability of exploitation is low, although not zero. The vulnerability is not listed in CISA’s KEV catalog, suggesting that there have not been reported large‑scale exploit campaigns that target this flaw. Based on the description, it is inferred that the backup/restore function is exposed over HTTP or HTTPS, so the likely attack vector requires access to that endpoint, potentially with authentication. Without an existing exploit chain, the risk remains defined by the ability to upload files that may be later executed or read by privileged processes.

Generated by OpenCVE AI on September 15, 2026 at 16:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HotelDruid to version 3.0.6 or later, which includes proper file validation in the backup/restore functionality.
  • If an immediate upgrade is not possible, restrict the backup/restore endpoint to trusted administrators and disable file uploads or enforce host‑based access controls to limit exposure of the backup/restore service to only trusted IP ranges, thereby reducing the attack surface.
  • Implement strict server‑side file type validation and MIME‑type checks when processing uploads to ensure only expected file formats are accepted before accepting a backup or restore operation.

Generated by OpenCVE AI on September 15, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Insufficient File Upload Sanitization in HotelDruid Backup/Restore Allows Arbitrary File Upload

Mon, 14 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Insufficient File Upload Sanitization in HotelDruid Backup/Restore

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Insufficient File Upload Sanitization in HotelDruid Backup/Restore

Mon, 14 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Description HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
First Time appeared Digitaldruid
Digitaldruid hoteldruid
Weaknesses CWE-434
CPEs cpe:2.3:a:digitaldruid:hoteldruid:*:*:*:*:*:*:*:*
Vendors & Products Digitaldruid
Digitaldruid hoteldruid
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Digitaldruid Hoteldruid
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:13:12.947Z

Reserved: 2023-06-07T00:00:00.000Z

Link: CVE-2023-34854

cve-icon Vulnrichment

Updated: 2026-09-14T15:03:57.300Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:57.437

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-34854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type