top of page
HUY VO
Information Security Engineer | MSc, CISSP
Search

Huy Vo
CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7
HotelDruid 3.0.7 weak password flaw (CVE-2025-25749) allows short, common, and reused passwords, exposing accounts to brute force.

Huy Vo
CVE-2025-25748-Cross-Site-Request-Forgery-CSRF-Vulnerability-in-HotelDruid-3.0.7
HotelDruid 3.0.7 CSRF (CVE-2025-25748) lets attackers change passwords via malicious links, risking account takeover.

Huy Vo
CVE-2025-25747 - Reflected XSS Vulnerability in HotelDruid 3.0.7
HotelDruid 3.0.7 Reflected XSS (CVE-2025-25747) allows injecting JavaScript via ripristina_backup, risking session hijacking & phishing.

Huy Vo
Coordinated-Vulnerability-Disclosure—HotelDruid-3.0.7
Multiple security vulnerabilities have been identified in HotelDruid 3.0.7, including Reflected Cross-Site Scripting (CVE-2025-25747), Cross
bottom of page