WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection
CVE-2022-47428
9.8CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 6 November 2023
Summary
The WpDevArt Booking Calendar and Appointment Booking System are susceptible to an SQL Injection vulnerability due to improper neutralization of special elements within SQL commands. This vulnerability allows attackers to manipulate SQL queries, potentially exposing sensitive database information. Users of affected versions, including 3.2.7 and earlier, are encouraged to implement the necessary security measures to safeguard their systems against this exploit.
Affected Version(s)
Booking calendar, Appointment Booking System <= 3.2.7
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
thiennv (Patchstack Alliance)