First published: Mon Jun 03 2024(Updated: )
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WpDevArt Booking Calendar | <=3.2.3 | |
WordPress Booking Calendar | <=3.2.3 | |
Booking Calendar | <3.2.4 |
Update to 3.2.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24373 is considered a high severity vulnerability due to its potential for manipulating hidden fields.
To fix CVE-2023-24373, upgrade the WpDevArt Booking calendar, Appointment Booking System to version 3.2.4 or later.
CVE-2023-24373 affects versions of WpDevArt Booking calendar, Appointment Booking System up to 3.2.3.
CVE-2023-24373 enables attackers to manipulate hidden fields, which may lead to unauthorized changes in booking data.
Yes, CVE-2023-24373 specifically affects the WordPress Booking calendar, Appointment Booking System plugin.