5.3
CVE-2022-4340
- EPSS 0.25%
- Veröffentlicht 02.01.2023 22:15:17
- Zuletzt bearbeitet 10.04.2025 19:15:53
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
BookingPress <= 1.0.30 - Unauthenticated Insecure Direct Object Reference
The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
Mögliche Gegenmaßnahme
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress: Update to version 1.0.31, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress
Version
* - 1.0.30
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Reputeinfosystems ≫ Bookingpress SwPlatformwordpress Version < 1.0.31
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.485 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|