Booking calendar, Appointment Booking System < 2.2.3 - Unauthenticated Parameter Manipulation
2018-06-07 00:00
B0UGStrategic Overview
StatusPatched in 2.2.3
Affected PluginBooking calendar, Appointment Booking System
Affected Version
<= 2.2.2CVSS7.5High
CVE
CVE-2018-10363Vulnerability Overview
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin in versions up to, and including, 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
Technical Analysis
REMEDIATION: Update to version 2.2.3, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C