Booking Calendar Contact是dwbooster个人开发者的一个预订日历插件。 dwbooster Booking Calendar Contact 1.1.24版本存在跨站脚本漏洞,该漏洞源于通过admin.php页面参数存在权限提升问题,可能导致未经身份验证的攻击者修改日历设置并注入存储型跨站脚本有效载荷。攻击者可通过GET请求将恶意JavaScript注入到'ict'和'ics'选项或日历'name'参数中,在管理界面显示或访问时执行任意脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dwbooster | Booking Calendar Contact | ≤ 1.1.24 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dwbooster | Booking Calendar Contact | 0 ~ 1.1.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2016-20068 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20069 | 8.2 HIGH | WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
| CVE-2016-20066 | 7.2 HIGH | WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting |
| CVE-2016-20070 | 6.4 MEDIUM | WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS |
| CVE-2016-20067 | 4.3 MEDIUM | WordPress CP Polls 1.0.8 Cross-Site Request Forgery |
No comments yet