CVE-2024-23091

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
30/07/2024
Last modified:
18/03/2025

Description

Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digitaldruid:hoteldruid:*:*:*:*:*:*:*:* 1.3.2 (excluding)