vendor:
Appointment Booking Calendar
by:
Joaquin Ramirez Martinez
5,5
CVSS
MEDIUM
Privilege escalation & Persistent XSS
N/A
CWE
Product Name: Appointment Booking Calendar
Affected Version From: 1.1.24
Affected Version To: 1.1.24
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 + Firefox + SQLMap 1.0
2016
WordPress appointment-booking-calendar <=1.1.24 - Privilege escalation (Managing calendars) & Persistent XSS
Multiple privilege escalation were found in appointment-booking-calendar plugin that allows remote low level and unauthenticated users to update calendar owners and options (allowing persistent XSS). Changing all appointment tables with UTF-8 charset, injecting persistent XSS into ´ict´ and ´ics´ options and setting ´CPABC_APPOINTMENTS_LOAD_SCRIPTS´ option to value ´1´.
Mitigation:
Update to the latest version of the plugin