PT-2024-18824 · WordPress · Salon Booking System
Cyc707
·
Published
2024-04-16
·
Updated
2024-08-01
·
CVE-2024-2102
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Salon booking system WordPress plugin versions prior to 9.6.3
Description
The issue arises from improper sanitization and escaping of the
Mobile Phone field and sms prefix parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the "Bookings" page and the malicious script is executed in the admin context.Recommendations
For versions prior to 9.6.3, update to version 9.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Bookings" page for admins until the update is applied. Avoid using the
sms prefix parameter in the booking process until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Salon Booking System