Debian Package Tracker
Register | Log in
Subscribe

hoteldruid

web-based property management system for hotels or B&Bs

Choose email to subscribe with

general
  • source: hoteldruid (main)
  • version: 3.0.8-1
  • maintainer: Marco Maria Francesco De Santis (DMD)
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.0.1-1
  • oldstable: 3.0.4-1
  • unstable: 3.0.8-1
versioned links
  • 3.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.0.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.0.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • hoteldruid (1 bugs: 0, 0, 1, 0)
action needed
Debci reports failed tests high
  • unstable: pass (log)
    The tests ran in 0:01:31
    Last run: 2026-05-26T17:05:11.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:01:24
    Last run: 2025-04-07T13:53:55.000Z
    Previous status: unknown

  • stable: fail (log)
    The tests ran in 0:00:30
    Last run: 2025-08-10T22:14:11.000Z
    Previous status: unknown

Created: 2025-08-11 Last update: 2026-08-13 06:33
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2023-43378: A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.
Created: 2025-03-12 Last update: 2026-08-02 20:32
3 security issues in trixie high

There are 3 open security issues in trixie.

3 important issues:
  • CVE-2025-25747: Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
  • CVE-2025-25748: A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.
  • CVE-2025-25749: An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
Created: 2025-03-12 Last update: 2025-03-31 13:25
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 2-day delay is over. Check why.
Created: 2026-04-13 Last update: 2026-08-13 06:32
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-08-13 06:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2024-04-07 Last update: 2026-03-31 15:01
testing migrations
  • excuses:
    • Migration status for hoteldruid (- to 3.0.8-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating hoteldruid would introduce bugs in testing: #1104020
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/h/hoteldruid.html
    • ∙ ∙ Autopkgtest for hoteldruid/3.0.8-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Pass
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ Required age reduced by 3 days because of autopkgtest
    • ∙ ∙ 207 days old (needed 2 days)
    • Not considered
news
[rss feed]
  • [2026-01-18] Accepted hoteldruid 3.0.8-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Alexandre Detiste)
  • [2025-04-21] hoteldruid REMOVED from testing (Debian testing watch)
  • [2023-12-04] hoteldruid 3.0.6-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-26] Accepted hoteldruid 3.0.6-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Tobias Frost)
  • [2023-10-25] hoteldruid REMOVED from testing (Debian testing watch)
  • [2023-06-21] hoteldruid 3.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-21] hoteldruid 3.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-14] Accepted hoteldruid 3.0.5-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: bage@debian.org)
  • [2022-04-29] hoteldruid 3.0.4-1 MIGRATED to testing (Debian testing watch)
  • [2022-04-22] Accepted hoteldruid 3.0.4-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: bage@debian.org)
  • [2021-11-19] hoteldruid 3.0.3-1 MIGRATED to testing (Debian testing watch)
  • [2021-11-11] Accepted hoteldruid 3.0.3-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: bage@debian.org)
  • [2020-02-24] hoteldruid 3.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-13] Accepted hoteldruid 3.0.1-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • [2019-11-21] hoteldruid 3.0.0-1 MIGRATED to testing (Debian testing watch)
  • [2019-11-10] Accepted hoteldruid 3.0.0-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • [2019-03-10] hoteldruid 2.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-27] Accepted hoteldruid 2.3.2-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • [2019-01-10] hoteldruid 2.3.0-2 MIGRATED to testing (Debian testing watch)
  • [2019-01-07] Accepted hoteldruid 2.3.0-2 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • [2018-11-21] hoteldruid 2.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2018-11-10] Accepted hoteldruid 2.3.0-1 (source all) into unstable (Marco Maria Francesco De Santis) (signed by: Herbert Parentes Fortes Neto)
  • [2018-10-19] hoteldruid 2.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2018-10-08] Accepted hoteldruid 2.2.4-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • [2018-06-15] hoteldruid 2.2.3-1 MIGRATED to testing (Debian testing watch)
  • [2018-06-04] Accepted hoteldruid 2.2.3-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • [2018-03-11] hoteldruid 2.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-01] Accepted hoteldruid 2.2.2-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Mattia Rizzolo)
  • [2017-08-09] hoteldruid 2.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2017-07-29] Accepted hoteldruid 2.2.1-1 (source) into unstable (Marco Maria Francesco De Santis) (signed by: Adam Borowski)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 1
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian
  • buildd: logs
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (98, -)
  • debian patches
  • debci

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing