The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Metrics
Affected Vendors & Products
References
History
Wed, 06 Nov 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nsqua
Nsqua simply Schedule Appointments |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:nsqua:simply_schedule_appointments:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Nsqua
Nsqua simply Schedule Appointments |
Tue, 05 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nsquared
Nsquared appointment Booking Calendar |
|
CPEs | cpe:2.3:a:nsquared:appointment_booking_calendar:*:*:*:*:*:*:*:* | |
Vendors & Products |
Nsquared
Nsquared appointment Booking Calendar |
|
Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
Title | Appointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-11-05T06:00:07.461Z
Updated: 2024-11-05T15:52:12.176Z
Reserved: 2024-08-16T12:20:01.517Z
Link: CVE-2024-7876
Vulnrichment
Updated: 2024-11-05T15:52:06.665Z
NVD
Status : Analyzed
Published: 2024-11-05T06:15:05.927
Modified: 2024-11-06T15:42:37.723
Link: CVE-2024-7876
Redhat
No data.