PT-2022-13864 · WordPress · Vikbooking Hotel Booking Engine & Pms

Gabriel3476

·

Published

2022-05-16

·

Updated

2022-05-24

·

CVE-2022-1407

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions VikBooking Hotel Booking Engine & PMS WordPress plugin versions prior to 1.5.8
Description The issue allows attackers to make a logged-in admin add a tracking campaign with XSS payloads via a CSRF attack, as there is no CSRF check in place when adding a tracking campaign, and the campaign fields are not escaped when outputting them in attributes.
Recommendations For versions prior to 1.5.8, update to version 1.5.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the tracking campaign feature to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1407

Affected Products

Vikbooking Hotel Booking Engine & Pms