Security Advisory

CVE-2022-0658

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-03-14 14:41:41
Last updated 2024-08-02 23:32:46
Assigner WPScan
State PUBLISHED

Description

The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection