vendor:
Booked Scheduler
by:
Besim ALTINOK
8.8
CVSS
HIGH
Authenticated Directory Traversal
22
CWE
Product Name: Booked Scheduler
Affected Version From: 2.7.7
Affected Version To: 2.7.7
Patch Exists: YES
Related CWE: N/A
CPE: a:bookedscheduler:booked_scheduler
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Xampp
2020
Booked Scheduler 2.7.7 – Authenticated Directory Traversal
Booked Scheduler is vulnerable to an authenticated directory traversal vulnerability. This vulnerability allows an authenticated user to access files outside of the web root directory. The vulnerable parameter is $tn, which is located in the manage_email_templates.php file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the server.
Mitigation:
Booked Scheduler should be updated to the latest version to mitigate this vulnerability.