CVE-2024-47316: WordPress Salon Booking Wordpress Plugin plugin <= 10.9 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 5, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon booking system: from n/a through <= 10.9.
Affected Software
3 affected components
Dimitri Grassi Salon booking system<=10.9
Dimitri Grassi WordPress Salon Booking plugin<=10.9
Salonbookingsystem Salon Booking System Wordpress<10.9.1
Remediation
Information
Update to 10.9.1 or a higher version.
Event History
Oct 5, 2024
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47316?
CVE-2024-47316 is rated as a high-severity vulnerability affecting the Salon Booking System.
2
How do I fix CVE-2024-47316?
To fix CVE-2024-47316, update the Salon Booking System to a version later than 10.9.
3
Which versions are affected by CVE-2024-47316?
CVE-2024-47316 affects Salon Booking System versions from n/a to 10.9.
4
What type of vulnerability is CVE-2024-47316?
CVE-2024-47316 is classified as an Authorization Bypass Through User-Controlled Key vulnerability.
5
Can CVE-2024-47316 be exploited?
Yes, CVE-2024-47316 can be exploited to bypass authorization controls in the affected systems.