First published: Mon Dec 05 2022(Updated: )
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Salon Booking System WordPress Plugin | <7.9 | |
<7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43487 is classified as a high-severity cross-site scripting vulnerability.
To fix CVE-2022-43487, upgrade the Salon Booking System plugin to version 7.9 or later.
Any user of the Salon Booking System plugin for WordPress versions prior to 7.9 is affected by CVE-2022-43487.
CVE-2022-43487 is a cross-site scripting (XSS) vulnerability that allows script injection.
Yes, CVE-2022-43487 can be exploited by a remote unauthenticated attacker.