CVE-2024-49304: WordPress Pinpoint Booking System plugin <= 2.9.9.5.7 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
Published Oct 17, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.7.
Affected Software
1 affected component
Dotonpaper Pinpoint Booking System<=2.9.9.5.7
Event History
Oct 17, 2024
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49304?
CVE-2024-49304 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that allows for Stored XSS attacks.
2
How do I fix CVE-2024-49304?
Fix CVE-2024-49304 by updating the Pinpoint Booking System to version 2.9.9.5.2 or later.
3
Which versions are affected by CVE-2024-49304?
CVE-2024-49304 affects Pinpoint Booking System versions from n/a up to 2.9.9.5.1.
4
What impact does CVE-2024-49304 have on users?
CVE-2024-49304 can potentially allow attackers to perform unauthorized actions on behalf of users, compromising their security.
5
Is there a recommended action for website owners regarding CVE-2024-49304?
Website owners should immediately upgrade their Pinpoint Booking System software to mitigate the risks associated with CVE-2024-49304.