Lucene search

K
nvd[email protected]NVD:CVE-2024-2102
HistoryApr 17, 2024 - 5:15 a.m.

CVE-2024-2102

2024-04-1705:15:48
web.nvd.nist.gov
4
wordpress
stored cross-site scripting
salon booking system

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

AI Score

5.6

Confidence

High

EPSS

0

Percentile

9.0%

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the ‘Mobile Phone’ field and ‘sms_prefix’ parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the ‘Bookings’ page and the malicious script is executed in the admin context.

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

AI Score

5.6

Confidence

High

EPSS

0

Percentile

9.0%