CVE-2019-9085

Publication date 24 June 2019

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.5 · Medium

Score breakdown

Description

Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id_transazione=1&numero_contratto=1&n_file=a query string to visualizza_contratto.php.

Status

Package Ubuntu Release Status
hoteldruid 25.10 questing
Fixed 2.3.2-1
25.04 plucky
Fixed 2.3.2-1
24.10 oracular
Fixed 2.3.2-1
24.04 LTS noble
Fixed 2.3.2-1
23.10 mantic
Fixed 2.3.2-1
23.04 lunar
Fixed 2.3.2-1
22.10 kinetic
Fixed 2.3.2-1
22.04 LTS jammy
Fixed 2.3.2-1
21.10 impish
Fixed 2.3.2-1
21.04 hirsute
Fixed 2.3.2-1
20.10 groovy
Fixed 2.3.2-1
20.04 LTS focal
Fixed 2.3.2-1
19.10 eoan
Fixed 2.3.2-1
19.04 disco Ignored end of life
18.10 cosmic Ignored end of life
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable
14.04 LTS trusty Not in release

Severity score breakdown

Parameter Value
Base score 6.5 · Medium
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H