Stored Cross-Site Scripting Vulnerability in Time Slots Booking Calendar by PHPJabbers
CVE-2023-48828

5.4MEDIUM

Key Information:

Vendor

PHPjabbers

Vendor
CVE Published:
7 December 2023

What is CVE-2023-48828?

The Time Slots Booking Calendar version 4.0 by PHPJabbers is susceptible to multiple Stored Cross-Site Scripting (XSS) vulnerabilities. These issues can be exploited through various parameters including name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name, allowing an attacker to inject malicious scripts. This can lead to session hijacking, data theft, or defacement of the web interface, compromising the security and integrity of affected installations.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.