RSS   Vulnerabilities for 'Availability booking calendar'   RSS

2023-12-07
 
CVE-2023-48207

CWE-1236
 

 
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

 
 
CVE-2023-48208

CWE-79
 

 
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.

 
 
CVE-2023-48825

CWE-79
 

 
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

 
 
CVE-2023-48831

CWE-400
 

 
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

 

 >>> Vendor: Phpjabbers 9 Products
Vacation rental script
Appointment scheduler
Event booking calendar
Rate me
Fundraising script
Car rental script
Time slots booking calendar
Availability booking calendar
Shuttle booking software


Copyright 2024, cxsecurity.com

 

Back to Top