The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/e922b788-7da5-43b4-9b05-839c8610252a | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/e922b788-7da5-43b4-9b05-839c8610252a | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/e922b788-7da5-43b4-9b05-839c8610252a - Exploit, Third Party Advisory |
15 Jul 2021, 15:20
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.1 |
References | (CONFIRM) https://wpscan.com/vulnerability/e922b788-7da5-43b4-9b05-839c8610252a - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:* |
12 Jul 2021, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-07-12 20:15
Updated : 2024-11-21 05:53
NVD link : CVE-2021-24429
Mitre link : CVE-2021-24429
CVE.ORG link : CVE-2021-24429
JSON object : View
Products Affected
salonbookingsystem
- salon_booking_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')