CVE-2024-2101: WordPress Plugin Salon Booking System < 9.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS)
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2101?
CVE-2024-2101 has a medium severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2101?
To fix CVE-2024-2101, upgrade the Salon Booking System WordPress plugin to version 9.6.3 or later.
Who is affected by CVE-2024-2101?
CVE-2024-2101 affects users of the Salon Booking System WordPress plugin prior to version 9.6.3.
What types of attacks can be conducted due to CVE-2024-2101?
CVE-2024-2101 allows for Stored Cross-Site Scripting attacks, where malicious scripts can be executed in the context of the admin's browser.
How can I identify if I am vulnerable to CVE-2024-2101?
You are vulnerable to CVE-2024-2101 if you are using the Salon Booking System WordPress plugin below version 9.6.3.