Stored Cross-Site Scripting Vulnerability in Time Slots Booking Calendar by PHPJabbers
CVE-2023-48828
5.4MEDIUM
What is CVE-2023-48828?
The Time Slots Booking Calendar version 4.0 by PHPJabbers is susceptible to multiple Stored Cross-Site Scripting (XSS) vulnerabilities. These issues can be exploited through various parameters including name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name, allowing an attacker to inject malicious scripts. This can lead to session hijacking, data theft, or defacement of the web interface, compromising the security and integrity of affected installations.