dwbooster Booking Calendar Contact Form是dwbooster个人开发者的一款用于网站预约管理的表单插件。 dwbooster Booking Calendar Contact Form 1.0.23及之前版本存在跨站脚本漏洞,该漏洞源于未验证用户权限和清理输入参数,导致权限提升和存储型跨站脚本,攻击者可通过price、name、calendar_language和email_confirmation_to_user参数注入恶意脚本,在管理员浏览器中执行任意JavaSc
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dwbooster | Booking Calendar Contact Form | ≤ 1.0.23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dwbooster | Booking Calendar Contact Form | 0 ~ 1.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2016-20068 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20069 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20066 | 7.2 HIGH | WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting |
| CVE-2016-20084 | 7.2 HIGH | WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS |
| CVE-2016-20067 | 4.3 MEDIUM | WordPress CP Polls 1.0.8 Cross-Site Request Forgery |
No comments yet