vendor:
Booking Calendar WordPress Plugin
by:
Summer of Pwnage
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Booking Calendar WordPress Plugin
Affected Version From: 6.2
Affected Version To: 6.2
Patch Exists: YES
Related CWE: N/A
CPE: a:wpdev:booking_calendar
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
SQL injection vulnerability in Booking Calendar WordPress Plugin
An SQL injection vulnerability exists in the Booking Calendar WordPress plugin. This vulnerability allows an attacker to view data from the database. The affected parameter is not properly sanitized or protected with an anti-Cross-Site Request Forgery token. Consequently, it can (also be exploited by luring the target user into clicking a specially crafted link or visiting a malicious website (or advertisement).
Mitigation:
This issue is resolved in Booking Calendar version 6.2.1.