PT-2024-18824 · WordPress · Salon Booking System

Cyc707

·

Published

2024-04-16

·

Updated

2024-08-01

·

CVE-2024-2102

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Salon booking system WordPress plugin versions prior to 9.6.3
Description The issue arises from improper sanitization and escaping of the Mobile Phone field and sms prefix parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the "Bookings" page and the malicious script is executed in the admin context.
Recommendations For versions prior to 9.6.3, update to version 9.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Bookings" page for admins until the update is applied. Avoid using the sms prefix parameter in the booking process until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2102

Affected Products

Salon Booking System