Booking Package <= 1.5.28 - Unauthenticated Sensitive Data Disclosure

2022-03-09 00:00
Huli, Cymetrics

Strategic Overview

Status
Patched in 1.5.29
Affected PluginBooking Package
Affected Version< 1.5.29
CVSS7.5High
CVECVE-2022-0709
View all Booking Package vulnerabilities

Vulnerability Overview

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

Technical Analysis

REMEDIATION: Update to version 1.5.29, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C