CVE-2022-43487: XSS
Published Dec 5, 2022
·Updated
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.
Affected Software
1 affected component
Salonbookingsystem Salon Booking System Wordpress<7.9
Event History
Dec 5, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43487?
CVE-2022-43487 is classified as a high-severity cross-site scripting vulnerability.
2
How do I fix CVE-2022-43487?
To fix CVE-2022-43487, upgrade the Salon Booking System plugin to version 7.9 or later.
3
Who is affected by CVE-2022-43487?
Any user of the Salon Booking System plugin for WordPress versions prior to 7.9 is affected by CVE-2022-43487.
4
What type of vulnerability is CVE-2022-43487?
CVE-2022-43487 is a cross-site scripting (XSS) vulnerability that allows script injection.
5
Can CVE-2022-43487 be exploited remotely?
Yes, CVE-2022-43487 can be exploited by a remote unauthenticated attacker.