Junglewise Threat Intelligence

CVE-2023-34854: HotelDruid insufficient file upload sanitation in backup/restore

CVE-2023-34854 · Severity: medium · CVSS 6.6 · Published 2026-09-14

Executive brief

HotelDruid is a web-based hotel management system that includes backup and restore functionality. The backup/restore feature fails to properly validate uploaded files, allowing an attacker to upload malicious files that could compromise the application and potentially the underlying server. This could lead to unauthorized data access, modification, or complete system compromise.

Technical details

The vulnerability exists in HotelDruid's backup/restore function, which does not adequately sanitize or validate uploaded files. This insufficient file upload validation is a classic file upload vulnerability that could allow an attacker to bypass restrictions and upload arbitrary files such as web shells, executables, or other malicious content. The attack vector is network-based, and depending on the application's file handling logic, may require user interaction or administrative access. An attacker exploiting this could achieve remote code execution or unauthorized access to sensitive hotel data. The vulnerability was patched in version 3.0.6.

Affected products

  • HotelDruid HotelDruid before 3.0.6

Timeline

  • 2023-07-14: disclosed
  • 2023: patched: Fixed in version 3.0.6

References