Stored XSS Vulnerability in Bookme Control Panel by neetech18
CVE-2018-8737

5.4MEDIUM

Key Information:

Vendor

Bylancer

Status
Vendor
CVE Published:
17 March 2018

What is CVE-2018-8737?

The Bookme Control Panel version 2.0 is susceptible to a stored cross-site scripting (XSS) flaw. This vulnerability arises when user-supplied input within the Customers 'Book Me' functionality is not properly sanitized. Attackers can exploit this issue by injecting malicious JavaScript code into the 'Name' and 'Note' fields, which is then rendered by the application in users' browsers. This leads to the potential for session hijacking, data theft, or other malicious actions affecting both users and the integrity of the web application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.