HIGH
Advanced Booking Calendar < 1.7.1 - Admin+ SQLi
Published Apr 11, 2022
7.2
HIGHCVSS 3.1
EPSS 1.48%
Description
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
Affected products
- Vendor n/a Product Advanced Booking Calendar Defaultunknown
Affected
- ≥ 1.7.1, < 1.7.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Advanced Booking Calendar | unknown | Affected
|
- < 1.7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24356 Advisory
- https://plugins.trac.wordpress.org/changeset/2695427 x_refsource_CONFIRMPatchThird Party Advisory
- https://wpscan.com/vulnerability/c5569317-b8c8-4524-8375-3e2369bdcc68 x_refsource_MISCExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24356 | Advisory | |
| https://plugins.trac.wordpress.org/changeset/2695427 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://wpscan.com/vulnerability/c5569317-b8c8-4524-8375-3e2369bdcc68 | x_refsource_MISCExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Apr 11, 2022
Updated Aug 2, 2024
Reserved Mar 17, 2022
Link CVE-2022-1006
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data