CVE-2024-43280: WordPress Salon Booking System plugin <= 10.8.1 - Open Redirection vulnerability
Published Aug 19, 2024
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1.
Affected Software
1 affected component
WordPress Salon Booking System plugin<=10.8.1
Remediation
Information
Update to 10.9 or a higher version.
Event History
Aug 19, 2024
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43280?
CVE-2024-43280 is classified as a medium severity vulnerability due to the potential for URL redirection to untrusted sites.
2
How do I fix CVE-2024-43280?
To fix CVE-2024-43280, update the Salon Booking System plugin to the latest version beyond 10.8.1.
3
What is the impact of CVE-2024-43280 on users?
CVE-2024-43280 can lead to phishing attacks as it allows attackers to redirect users to malicious sites.
4
Which versions of the Salon Booking System are affected by CVE-2024-43280?
CVE-2024-43280 affects the Salon Booking System plugin versions up to and including 10.8.1.
5
What type of vulnerability is CVE-2024-43280?
CVE-2024-43280 is an Open Redirect vulnerability that allows malicious redirection by manipulating URL parameters.