Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-62865
HistoryJul 31, 2023 - 12:00 a.m.

Availability Booking Calendar PHP Cross Site Scripting Vulnerability

2023-07-3100:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
gz scripts
open source
booking calendar
php
cross-site scripting
version 1.0
index.php
promo_code
user-supplied data
filtering
escaping
attacker
payload
arbitrary web script
html
web security

0.001 Low

EPSS

Percentile

25.1%

Availability Booking Calendar PHP is GZ Scripts open source an availability booking calendar system . Availability Booking Calendar PHP v1.0 version of a cross-site scripting vulnerability , the vulnerability stems from the file index.php parameter promo_code on the user-supplied data lack of effective filtering and escaping , an attacker can exploit the vulnerability by injecting a well-designed payload to execute arbitrary Web script or HTML.

0.001 Low

EPSS

Percentile

25.1%

Related for CNVD-2023-62865