Unknown Salon Booking System Pro vulnerabilities
2 known vulnerabilities affecting unknown/salon_booking_system_pro.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-0920HIGHCVSS 7.5≥ 7.6.3, < 7.6.32022-04-11
CVE-2022-0920 [HIGH] CWE-863 CVE-2022-0920: The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisatio
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
cvelistv5nvd
CVE-2022-0919MEDIUMCVSS 5.3≥ 7.6.3, < 7.6.32022-04-11
CVE-2022-0919 [MEDIUM] CWE-862 CVE-2022-0919: The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisatio
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.
cvelistv5nvd