PT-2023-30971 · Unknown · Time Slots Booking Calendar

Publicado

2023-12-06

·

Atualizado

2023-12-09

·

CVE-2023-48827

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Time Slots Booking Calendar version 4.0
Description The issue concerns Multiple HTML Injection problems. These issues can be exploited via several parameters, including name, plugin sms api key, plugin sms country code, calendar id, title, country name, or customer name.
Recommendations For Time Slots Booking Calendar version 4.0, as a temporary workaround, consider restricting the input for the name, plugin sms api key, plugin sms country code, calendar id, title, country name, and customer name parameters to prevent HTML injection until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-48827

Produtos afetados

Time Slots Booking Calendar