The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins
History

Fri, 27 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Nsqua
Nsqua simply Schedule Appointments
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:nsqua:simply_schedule_appointments:*:*:*:*:*:wordpress:*:*
Vendors & Products Nsqua
Nsqua simply Schedule Appointments

Fri, 13 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Nqquared
Nqquared appointment Booking Calendar
CPEs cpe:2.3:a:nqquared:appointment_booking_calendar:*:*:*:*:*:*:*:*
Vendors & Products Nqquared
Nqquared appointment Booking Calendar
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins
Title Appointment Booking Calendar < 1.6.7.43 - Admin+ Template Injection to RCE
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-13T06:00:03.731Z

Updated: 2024-09-13T13:55:38.304Z

Reserved: 2024-07-26T11:56:34.810Z

Link: CVE-2024-7129

cve-icon Vulnrichment

Updated: 2024-09-13T13:46:25.381Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T06:15:15.507

Modified: 2024-09-27T18:26:27.560

Link: CVE-2024-7129

cve-icon Redhat

No data.