First published: Mon Dec 09 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy Appointments allows Stored XSS.This issue affects Easy Appointments: from n/a through 3.10.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Appointments | <3.11.1 | |
Easy!Appointments by Alex Tselegidis | <=3.10.7 | |
Easy Appointments | <=3.10.7 |
Update to 3.11.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30748 has a moderate severity level due to its potential for stored Cross-site Scripting (XSS) attacks.
To fix CVE-2023-30748, update Easy Appointments to version 3.10.8 or later.
CVE-2023-30748 affects Easy Appointments versions up to and including 3.10.7.
CVE-2023-30748 is an improper neutralization of input during web page generation that leads to stored XSS.
The vendor associated with CVE-2023-30748 is Nikola Loncar, the developer of Easy Appointments.