Beveiligingsadvies

CVE-2022-0658

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-03-14 14:41:41
Laatst bijgewerkt 2024-08-02 23:32:46
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection