PT-2024-18823 · WordPress · Salon Booking System
Priyanka Pande
·
Published
2024-04-16
·
Updated
2024-07-03
·
CVE-2024-2101
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Salon booking system WordPress plugin versions prior to 9.6.3
Description
The issue arises from improper sanitization and escaping of the
Mobile Phone field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload is triggered when an admin visits the "Customers" page, and the malicious script is executed in the admin context.Recommendations
For versions prior to 9.6.3, update to version 9.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Customers" page for admins until the update is applied. Additionally, avoid using the
Mobile Phone field in the booking system until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salon Booking System