HotelDruid is a hotel management software that provides users with tools to manage bookings, reservations, check-in and check-out processes, billing, and more. This software is most commonly used by small and medium-sized hotels looking to streamline their operations and improve customer experience. With its intuitive interface and customizable options, HotelDruid makes it easy for hotel managers to keep track of their business and optimize their workflows.

Recently, a vulnerability known as CVE-2019-8937 has been discovered in HotelDruid version 2.3.0. This vulnerability affects several parameters including nsextt, cambia1, mese_fine, origine, and anno in four different PHP pages: creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php. The vulnerability allows an attacker to inject malicious code into these variables, which can then be executed by any unsuspecting user who uses the affected pages.

If this vulnerability is exploited, it can lead to a number of serious consequences for hotel owners using HotelDruid. For example, an attacker could use the injected code to steal sensitive customer information such as credit card details, social security numbers, and other personally identifiable information. They could also use the same code to disrupt the normal operation of the hotel's website, causing it to crash or malfunction. In addition, the attacker could gain unauthorized access to sensitive business data, including financial records, employee information, and other confidential information.

