Booking calendar, Appointment Booking System < 2.2.3 - Unauthenticated Parameter Manipulation

2018-06-07 00:00
B0UG

Strategic Overview

Status
Patched in 2.2.3
Affected Version<= 2.2.2
CVSS7.5High
CVECVE-2018-10363
View all Booking calendar, Appointment Booking System vulnerabilities

Vulnerability Overview

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin in versions up to, and including, 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.

Technical Analysis

REMEDIATION: Update to version 2.2.3, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C