The plugin does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection.
id: CVE-2022-0658
info:
name: CommonsBooking < 2.6.8 - SQL Injection
author: theamanrawat
sev
...