CVE-2024-2429: Salon booking system <= 9.6.5 - Settings Update via CSRF
The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2429?
CVE-2024-2429 has been classified as a moderate severity vulnerability due to the potential for unauthorized settings changes by attackers.
How do I fix CVE-2024-2429?
To fix CVE-2024-2429, update the Salon booking system plugin to version 9.6.6 or higher, which includes the necessary CSRF protection.
What does CVE-2024-2429 exploit?
CVE-2024-2429 exploits the lack of a CSRF check when updating settings in the Salon booking system plugin.
Who is affected by CVE-2024-2429?
Users of the Salon booking system plugin for WordPress versions up to and including 9.6.5 are affected by CVE-2024-2429.
Can CVE-2024-2429 be remotely exploited?
CVE-2024-2429 cannot be remotely exploited without the attacker being logged into the admin account.