PT-2020-15678 · Etoile Web Design · Etoile Web Design Ultimate Appointment Booking & Scheduling Wordpress Plugin
Published
2020-08-26
·
Updated
2024-02-14
·
CVE-2020-24313
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin versions 1.1.9 and lower
Description
The issue is related to a reflected XSS vulnerability. It occurs because the
Appointment ID GET parameter value is not properly sanitized before being echoed back inside an input tag. This allows attackers to exploit the vulnerability using a specially crafted URL.Recommendations
For Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin versions 1.1.9 and lower, consider updating to a version where this issue is fixed, as the current version does not properly sanitize the
Appointment ID parameter, leading to a reflected XSS vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etoile Web Design Ultimate Appointment Booking & Scheduling Wordpress Plugin