Bug#929136: hoteldruid: CVE-2019-8937

2019-05-18 Thread Salvatore Bonaccorso
Source: hoteldruid Source-Version: 2.3.2-1 Hi Marco, On Sat, May 18, 2019 at 03:21:46PM +0200, Marco M. F. De Santis wrote: > Hello Salvatore, > CVE-2019-8937 is already fixed in hoteldruid 2.3.2 as a consequence of the > other CVEs. This CVE had not been reported to me when 2.3.2 was released.

Bug#929136: hoteldruid: CVE-2019-8937

2019-05-18 Thread Marco M. F. De Santis
Hello Salvatore, CVE-2019-8937 is already fixed in hoteldruid 2.3.2 as a consequence of the other CVEs. This CVE had not been reported to me when 2.3.2 was released. Regards, Marco

Bug#929136: hoteldruid: CVE-2019-8937

2019-05-17 Thread Salvatore Bonaccorso
Source: hoteldruid Version: 2.3.2-1 Severity: grave Tags: security upstream Hi, The following vulnerability was published for hoteldruid. CVE-2019-8937[0]: | HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, | origine, and anno parameters in creaprezzi.php, tabella3.php, |