PT-2024-18824 · WordPress · Salon Booking System

·

CVE-2024-2102

·

Published

2024-04-16

·

Updated

2024-08-01

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Salon booking system WordPress plugin versions prior to 9.6.3
Description The issue arises from improper sanitization and escaping of the Mobile Phone field and sms prefix parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the "Bookings" page and the malicious script is executed in the admin context.
Recommendations For versions prior to 9.6.3, update to version 9.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Bookings" page for admins until the update is applied. Avoid using the sms prefix parameter in the booking process until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2102

Affected Products

Salon Booking System