vendor:
Appointment Scheduler
by:
HackXBack
8,8
CVSS
HIGH
Cross Site Scripting, Cross Site Request Forgery, Local File disclure
79,352,22
CWE
Product Name: Appointment Scheduler
Affected Version From: V2.0
Affected Version To: V2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:phpjabbers:appointment_scheduler
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Appointment Scheduler V2.0 – Multiple Vulnerabilities
Cross Site Scripting: An attacker can inject malicious JavaScript code into the vulnerable application. Cross Site Request Forgery: An attacker can add an admin user to the application. Local File disclure: An attacker can access sensitive files from the application.
Mitigation:
Implement input validation, use of anti-CSRF tokens, and proper access control.