PT-2015-7521 · WordPress · Appointment Booking Calendar

Published

2015-09-29

·

Updated

2018-10-09

·

CVE-2015-7319

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Appointment Booking Calendar plugin versions prior to 1.1.8
Description The issue allows remote attackers to execute arbitrary SQL commands. This is related to updating the username via unspecified vectors in the cpabc appointments admin int calendar list.inc.php file.
Recommendations For versions prior to 1.1.8, update to version 1.1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the cpabc appointments admin int calendar list.inc.php file until a patch is applied. Avoid using the username variable in related API endpoints until the issue is resolved.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7319

Affected Products

Appointment Booking Calendar