Bug#917099: hoteldruid: CVE-2018-1000871, SQL injection

2018-12-26 Thread Marco M. F. De Santis
Hello Markus, this bug can be exploited only if you already have access to hoteldruid administrator account. Also it only affects mysql database, by default this debian package uses sqlite. Anyway a new version should be out soon. Regards, Marco Il 22/12/18 16:39, Markus Koschany ha

Bug#917099: hoteldruid: CVE-2018-1000871, SQL injection

2018-12-22 Thread Markus Koschany
Package: hoteldruid X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for hoteldruid. I couldn't find a bug tracker or code repository for hoteldruid but it seems you are involved in upstream development somehow. Are you aware of