CVE-2022-1407: VikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-1407.
What is the severity level of CVE-2022-1407?
CVE-2022-1407 has a severity level of medium.
What is the affected software of CVE-2022-1407?
The affected software of CVE-2022-1407 is VikBooking Hotel Booking Engine & PMS WordPress plugin before version 1.5.8.
What is the CWE category of CVE-2022-1407?
The CWE category of CVE-2022-1407 is CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-352 (Cross-Site Request Forgery (CSRF)).
Is there a fix available for CVE-2022-1407?
Yes, the fix for CVE-2022-1407 is to update the VikBooking Hotel Booking Engine & PMS WordPress plugin to version 1.5.8 or newer.