First published: Thu Aug 03 2023(Updated: )
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Availability Booking Calendar | =5.0 | |
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4110 is medium.
PHP Jabbers Availability Booking Calendar 5.0 is affected by CVE-2023-4110.
CVE-2023-4110 is a cross-site scripting vulnerability.
The attack for CVE-2023-4110 can be launched remotely using the manipulation of the 'session_id' parameter.
Yes, here are some references for CVE-2023-4110: - [VulDB](https://vuldb.com/?id.235957) - [VulDB](https://vuldb.com/?ctiid.235957) - [PacketStorm Security](http://packetstormsecurity.com/files/173926/PHPJabbers-Availability-Booking-Calendar-5.0-Cross-Site-Scripting.html)