The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-10-08T19:08:16.135Z

Reserved: 2023-04-11T10:40:01.555Z

Link: CVE-2023-1977

cve-icon Vulnrichment

Updated: 2024-08-02T06:05:27.082Z

cve-icon NVD

Status : Modified

Published: 2023-08-16T12:15:12.510

Modified: 2024-11-21T07:40:16.050

Link: CVE-2023-1977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.