PT-2023-30971 · Unknown · Time Slots Booking Calendar

Published

2023-12-06

·

Updated

2023-12-09

·

CVE-2023-48827

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Time Slots Booking Calendar version 4.0
Description The issue concerns Multiple HTML Injection problems. These issues can be exploited via several parameters, including name, plugin sms api key, plugin sms country code, calendar id, title, country name, or customer name.
Recommendations For Time Slots Booking Calendar version 4.0, as a temporary workaround, consider restricting the input for the name, plugin sms api key, plugin sms country code, calendar id, title, country name, and customer name parameters to prevent HTML injection until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48827

Affected Products

Time Slots Booking Calendar