Impact
HotelDruid versions before 3.0.6 use inadequate validation when files are uploaded during backup and restore operations. This flaw permits uploading of arbitrary files to the server impact can range from accidental exposure of data to execution of malicious code if the uploaded file is later processed by privileged components. The description does not specify that it leads directly to arbitrary code execution, but it poses a risk of improper file placement and subsequent exploitation if those files are executed or parsed. Based on the description, it is inferred that the backup/restore functionality is exposed over HTTP or HTTPS.
Affected Systems
Any deployment of HotelDruid prior to version 3.0.6 is affected. This includes all installations of the digitaldruid:HotelDruid application identified by the vendor and product names in the CNA data. No specific subsystem or operating system is singled out, so the vulnerability applies broadly to all affected host environments where the backup/restore endpoint is reachable.
Risk and Exploitability
The CVSS score is 6.6, indicating that while exploitation is considered feasible, it requires that the attacker can reach the function and successfully upload a file. The EPSS score is < 1%, meaning the probability of exploitation is low, although not zero. The vulnerability is not listed in CISA’s KEV catalog, suggesting that there have not been reported large‑scale exploit campaigns that target this flaw. Based on the description, it is inferred that the backup/restore function is exposed over HTTP or HTTPS, so the likely attack vector requires access to that endpoint, potentially with authentication. Without an existing exploit chain, the risk remains defined by the ability to upload files that may be later executed or read by privileged processes.
OpenCVE Enrichment