PT-2024-18823 · WordPress · Salon Booking System

Priyanka Pande

·

Published

2024-04-16

·

Updated

2024-07-03

·

CVE-2024-2101

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Salon booking system WordPress plugin versions prior to 9.6.3
Description The issue arises from improper sanitization and escaping of the Mobile Phone field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload is triggered when an admin visits the "Customers" page, and the malicious script is executed in the admin context.
Recommendations For versions prior to 9.6.3, update to version 9.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Customers" page for admins until the update is applied. Additionally, avoid using the Mobile Phone field in the booking system until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2101

Affected Products

Salon Booking System