vendor:
Vacation Rental Script
by:
HackXBack
8,8
CVSS
HIGH
Cross Site Request Forgery and Multiple Cross Site Scripting
352, 79
CWE
Product Name: Vacation Rental Script
Affected Version From: V3.0
Affected Version To: V3.0
Patch Exists: YES
Related CWE: N/A
CPE: a:phpjabbers:vacation_rental_script
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Vacation Rental Script V3.0 – Multiple Vulnerabilties
Cross Site Request Forgery (CSRF) vulnerability in Vacation Rental Script V3.0 allows remote attackers to hijack the authentication of administrators for requests that create new admin accounts. Multiple Cross Site Scripting (XSS) vulnerabilities in Vacation Rental Script V3.0 allow remote attackers to inject arbitrary web script or HTML via the i18n[1][name] parameter to index.php in the Types and Features modules.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of the software.