Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-24555
HistoryAug 23, 2021 - 12:15 p.m.

Sql injection

2021-08-2312:15:00
PRIOn knowledge base
www.prio-n.com
1

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.6%

The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check, making it available to any authenticated user.

CPENameOperatorVersion
diary-availability-calendarle1.0.3

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.6%

Related for PRION:CVE-2021-24555