The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'sms_prefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the malicious script is executed in the admin context.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salonbookingsystem
Salonbookingsystem salon Booking System |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Salonbookingsystem
Salonbookingsystem salon Booking System |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T19:03:38.794Z
Reserved: 2024-03-01T16:20:45.609Z
Link: CVE-2024-2102
Updated: 2024-08-01T19:03:38.794Z
Status : Analyzed
Published: 2024-04-17T05:15:48.650
Modified: 2025-04-14T13:42:32.573
Link: CVE-2024-2102
No data.
OpenCVE Enrichment
No data.
Weaknesses