First published: Mon Nov 06 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Booking Calendar | <3.2.8 |
Update to 3.2.8 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47428 is a SQL Injection vulnerability in the WpDevArt Booking calendar, Appointment Booking System plugin for WordPress.
CVE-2022-47428 has a severity rating of 9.8, which is considered critical.
CVE-2022-47428 allows SQL Injection attacks on the Booking calendar, Appointment Booking System plugin.
Versions up to and including 3.2.7 of the Booking calendar, Appointment Booking System plugin are affected by CVE-2022-47428.
Yes, a patch or fix is available for CVE-2022-47428. Please refer to the following link for more information: [link](https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve)