PT-2024-39851 · Craig Rodway · Classroombookings

Cream3Gg

+1

·

Published

2024-10-10

·

Updated

2024-10-17

·

CVE-2024-9806

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Craig Rodway Classroombookings versions up to 2.8.6
Description A vulnerability has been found in the component Room Page, affecting unknown code of the file /rooms/fields. The manipulation of the argument Name leads to cross-site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Craig Rodway Classroombookings versions up to 2.8.6, upgrade to version 2.8.7 to address this issue. As a temporary workaround, consider restricting access to the Name field in the Room Page until the upgrade is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-9806

Affected Products

Classroombookings