PT-2022-14199 · WordPress · Rezgo Online Booking

Cydave

·

Published

2022-08-22

·

Updated

2022-08-25

·

CVE-2022-1932

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rezgo Online Booking WordPress plugin versions prior to 4.1.8
Description The issue is related to a Reflected Cross-Site Scripting problem. This occurs because some parameters are not properly sanitised and escaped before being outputted back in a page. The issue can be exploited through a Local File Inclusion (LFI) in an AJAX action or by making a direct call to the affected file.
Recommendations For versions prior to 4.1.8, update to version 4.1.8 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-1932

Affected Products

Rezgo Online Booking