Reflected Cross-Site Scripting in Bus Ticket Booking Plugin for WordPress
CVE-2023-4067
6.1MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 2 August 2023
Summary
The Bus Ticket Booking with Seat Reservation plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate input validation and output encoding. Attackers can exploit this vulnerability by manipulating the 'tab_date' and 'tab_date_r' parameters in versions up to 5.2.3. If exploited, this allows unauthenticated individuals to inject malicious scripts into web pages, which may execute in the user's browser upon interaction, potentially leading to session hijacking or unauthorized actions on behalf of the user.
Affected Version(s)
Bus Ticket Booking with Seat Reservation * <= 5.2.3
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vincenzo Turturro
Gianluca Parisi
Vincenzo Cantatore