MEDIUM
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress
Published Mar 4, 2020
4.8
MEDIUMCVSS 3.1
EPSS 3.30%
Description
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
Affected products
No data.
- < 1.3.35
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9 x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30192 Advisory
- https://wordpress.org/plugins/appointment-booking-calendar/#developers x_refsource_MISCRelease NotesThird Party Advisory
- https://wpvulndb.com/vulnerabilities/10110 x_refsource_MISCThird Party Advisory
- https://www.hotdreamweaver.com/support/view.php?id=815925 x_refsource_MISCPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9 | x_refsource_MISCExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30192 | Advisory | |
| https://wordpress.org/plugins/appointment-booking-calendar/#developers | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://wpvulndb.com/vulnerabilities/10110 | x_refsource_MISCThird Party Advisory | |
| https://www.hotdreamweaver.com/support/view.php?id=815925 | x_refsource_MISCPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 4, 2020
Updated Aug 4, 2024
Reserved Feb 24, 2020
Link CVE-2020-9371
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-30192 Assigner mitre
Published Mar 4, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-30192