CVE-2023-48831
- EPSS 0.3%
- Veröffentlicht 07.12.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 08:32:31
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
CVE-2023-48825
- EPSS 0.2%
- Veröffentlicht 07.12.2023 07:15:10
- Zuletzt bearbeitet 21.11.2024 08:32:30
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
CVE-2023-48207
- EPSS 0.18%
- Veröffentlicht 07.12.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:31:13
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
CVE-2023-48208
- EPSS 0.26%
- Veröffentlicht 07.12.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:31:13
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
CVE-2023-36132
- EPSS 0.11%
- Veröffentlicht 04.08.2023 00:15:12
- Zuletzt bearbeitet 21.11.2024 08:09:19
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
CVE-2023-36133
- EPSS 0.11%
- Veröffentlicht 04.08.2023 00:15:12
- Zuletzt bearbeitet 21.11.2024 08:09:19
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
CVE-2023-36131
- EPSS 0.1%
- Veröffentlicht 04.08.2023 00:15:11
- Zuletzt bearbeitet 21.11.2024 08:09:19
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
CVE-2023-4110
- EPSS 7.65%
- Veröffentlicht 03.08.2023 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:24
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cro...