CVE-2024-2102: Salon booking system < 9.6.3 - Unauthenticated Stored XSS
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'smsprefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the malicious script is executed in the admin context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2102?
CVE-2024-2102 has been classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2102?
To mitigate CVE-2024-2102, you should update the Salon booking system WordPress plugin to version 9.6.3 or later.
What does CVE-2024-2102 affect?
CVE-2024-2102 affects versions of the Salon booking system WordPress plugin prior to 9.6.3.
What type of attack can be performed using CVE-2024-2102?
CVE-2024-2102 allows for Stored Cross-Site Scripting attacks, which can trigger malicious payloads in an admin view.
Who is impacted by CVE-2024-2102?
Users of the Salon booking system WordPress plugin who have not updated to version 9.6.3 are at risk for impacting their website security.