First published: Wed Apr 17 2024(Updated: )
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'sms_prefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the malicious script is executed in the admin context.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Salon Booking System | <9.6.3 | |
Salon Booking System WordPress Plugin | <9.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2102 has been classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
To mitigate CVE-2024-2102, you should update the Salon booking system WordPress plugin to version 9.6.3 or later.
CVE-2024-2102 affects versions of the Salon booking system WordPress plugin prior to 9.6.3.
CVE-2024-2102 allows for Stored Cross-Site Scripting attacks, which can trigger malicious payloads in an admin view.
Users of the Salon booking system WordPress plugin who have not updated to version 9.6.3 are at risk for impacting their website security.