PT-2023-10278 · Unknown · Cp Appointment Calendar Plugin

Published

2023-04-10

·

Updated

2024-05-17

·

CVE-2015-10099

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CP Appointment Calendar Plugin version 1.1.5 and earlier
Description A critical vulnerability has been found in the CP Appointment Calendar Plugin. This issue affects the dex process ready to go appointment function of the dex appointments.php file. The manipulation of the itemnumber argument leads to SQL injection. It is possible to initiate the attack remotely.
Recommendations To fix this issue, apply the patch named e29a9cdbcb0f37d887dd302a05b9e8bf213da01d. As a temporary workaround, consider restricting access to the dex appointments.php file or disabling the dex process ready to go appointment function until the patch is applied. Avoid using the itemnumber argument in the affected function until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2015-10099

Affected Products

Cp Appointment Calendar Plugin