Stored XSS Vulnerability in Bookme Control Panel by neetech18
CVE-2018-8737
5.4MEDIUM
What is CVE-2018-8737?
The Bookme Control Panel version 2.0 is susceptible to a stored cross-site scripting (XSS) flaw. This vulnerability arises when user-supplied input within the Customers 'Book Me' functionality is not properly sanitized. Attackers can exploit this issue by injecting malicious JavaScript code into the 'Name' and 'Note' fields, which is then rendered by the application in users' browsers. This leads to the potential for session hijacking, data theft, or other malicious actions affecting both users and the integrity of the web application.
