Lucene search

K
cvePatchstackCVE-2023-50851
HistoryDec 28, 2023 - 12:15 p.m.

CVE-2023-50851

2023-12-2812:15:43
CWE-89
Patchstack
web.nvd.nist.gov
26
cve
2023
50851
sql injection
n squared
appointment booking calendar
simply schedule appointments booking plugin

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

19.3%

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in N Squared Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin.This issue affects Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin: from n/a before 1.6.6.1.

Affected configurations

Nvd
Vulners
Node
nsquasimply_schedule_appointmentsRange<1.6.6.1wordpress
VendorProductVersionCPE
nsquasimply_schedule_appointments*cpe:2.3:a:nsqua:simply_schedule_appointments:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "simply-schedule-appointments",
    "product": "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin",
    "vendor": "N Squared",
    "versions": [
      {
        "changes": [
          {
            "at": "1.6.6.1",
            "status": "unaffected"
          }
        ],
        "lessThan": "1.6.6.1",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

19.3%

Related for CVE-2023-50851