Unknown Salon Booking System vulnerabilities
7 known vulnerabilities affecting unknown/salon_booking_system.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2024-2439MEDIUMCVSS 4.8≤ 9.6.52024-04-26
CVE-2024-2439 [MEDIUM] CWE-79 CVE-2024-2439: The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its set
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
cvelistv5nvd
CVE-2024-2603MEDIUMCVSS 6.3≤ 9.6.52024-04-26
CVE-2024-2603 [MEDIUM] CWE-79 CVE-2024-2603: The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its set
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (
cvelistv5nvd
CVE-2024-2429MEDIUMCVSS 4.3≤ 9.6.52024-04-26
CVE-2024-2429 [MEDIUM] CWE-352 CVE-2024-2429: The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updat
The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
cvelistv5nvd
CVE-2024-2101MEDIUMCVSS 5.7fixed in 9.6.32024-04-17
CVE-2024-2101 [MEDIUM] CWE-79 CVE-2024-2101: The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mo
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.
cvelistv5nvd
CVE-2024-2102MEDIUMCVSS 4.7fixed in 9.6.32024-04-17
CVE-2024-2102 [MEDIUM] CWE-79 CVE-2024-2102: The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mo
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'sms_prefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the malicious script is executed in the a
cvelistv5nvd
CVE-2022-0920HIGHCVSS 7.5≥ 7.6.3, < 7.6.32022-04-11
CVE-2022-0920 [HIGH] CWE-863 CVE-2022-0920: The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisatio
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
cvelistv5nvd
CVE-2022-0919MEDIUMCVSS 5.3≥ 7.6.3, < 7.6.32022-04-11
CVE-2022-0919 [MEDIUM] CWE-862 CVE-2022-0919: The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisatio
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.
cvelistv5nvd