Reflected Cross-Site Scripting in Bus Ticket Booking Plugin for WordPress
CVE-2023-4067

6.1MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
2 August 2023

Summary

The Bus Ticket Booking with Seat Reservation plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate input validation and output encoding. Attackers can exploit this vulnerability by manipulating the 'tab_date' and 'tab_date_r' parameters in versions up to 5.2.3. If exploited, this allows unauthenticated individuals to inject malicious scripts into web pages, which may execute in the user's browser upon interaction, potentially leading to session hijacking or unauthorized actions on behalf of the user.

Affected Version(s)

Bus Ticket Booking with Seat Reservation * <= 5.2.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincenzo Turturro
Gianluca Parisi
Vincenzo Cantatore
.