First published: Thu Dec 07 2023(Updated: )
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPJabbers Availability Booking Calendar | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48207 has been classified with a medium severity level due to its potential for CSV injection which can lead to data manipulation.
To fix CVE-2023-48207, update the Availability Booking Calendar to the latest version or sanitize inputs to prevent CSV injection.
CVE-2023-48207 affects Availability Booking Calendar version 5.0.
Yes, CVE-2023-48207 can potentially allow remote attackers to execute arbitrary commands through crafted CSV files.
Symptoms of exploitation of CVE-2023-48207 may include unexpected file downloads and unauthorized data manipulation in the application.