Salonbookingsystem Salon Booking System vulnerabilities
22 known vulnerabilities affecting salonbookingsystem/salon_booking_system.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH6MEDIUM12
Vulnerabilities
Page 2 of 2
CVE-2022-0919MEDIUMCVSS 5.3fixed in 7.6.32022-04-11
CVE-2022-0919 [MEDIUM] CWE-862 CVE-2022-0919: The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisatio
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.
nvd
CVE-2021-24429MEDIUMCVSS 6.1fixed in 6.3.12021-07-12
CVE-2021-24429 [MEDIUM] CWE-79 CVE-2021-24429: The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the Fir
The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" p
nvd
← Previous2 / 2