First published: Fri Jun 23 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Magepeople Booking & Rental Manager | <=1.2.1 |
Update to 1.2.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35048 is classified as a medium severity vulnerability due to its potential for exploitation in web applications.
To fix CVE-2023-35048, it is recommended to update the MagePeople Team Booking and Rental Manager for Bike plugin to version 1.2.2 or later.
CVE-2023-35048 is an authenticated stored cross-site scripting (XSS) vulnerability.
CVE-2023-35048 affects versions of the MagePeople Team Booking and Rental Manager plugin up to and including 1.2.1.
Users of the MagePeople Team Booking and Rental Manager for Bike plugin who have version 1.2.1 or earlier installed are affected by CVE-2023-35048.