PT-2021-15959 · WordPress · Salon Booking System

Phu Tran

·

Published

2021-07-12

·

Updated

2021-07-15

·

CVE-2021-24429

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Salon booking system WordPress plugin versions prior to 6.3.1
Description The issue arises from the improper sanitization and escaping of the First Name field when booking an appointment, allowing low-privilege users to set JavaScript, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The malicious script is executed in the admin context when an admin visits the "Calendar" page.
Recommendations For versions prior to 6.3.1, update to version 6.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Calendar" page for admins until the update is applied. Additionally, limiting the ability of low-privilege users, such as subscribers, to book appointments or set custom First Name fields may help mitigate the risk.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24429

Affected Products

Salon Booking System