First published: Fri Jul 07 2023(Updated: )
A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-233295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gzscripts Availability Booking Calendar Php | =1.8 | |
=1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3543 is a vulnerability found in GZ Scripts Availability Booking Calendar PHP 1.8, classified as a problematic cross-site scripting vulnerability.
The severity of CVE-2023-3543 is medium with a CVSS score of 6.1.
The vulnerability affects an unknown part of the file load.php, impacting the component's HTTP POST Request Handler.
CVE-2023-3543 can allow an attacker to manipulate specific input arguments to execute cross-site scripting attacks.
To fix CVE-2023-3543, it is recommended to update GZ Scripts Availability Booking Calendar PHP to a version that addresses the vulnerability.