SQL Injection Vulnerability in Booking Calendar Plugin from WpDevArt
CVE-2024-10856

6.5MEDIUM

Key Information:

Vendor

WPdevart

Vendor
CVE Published:
24 December 2024

What is CVE-2024-10856?

The Booking Calendar plugin by WpDevArt is exposed to a significant security flaw characterized by a time-based, blind SQL injection. This vulnerability is triggered through an inadequate escape mechanism on the 'id' parameter in the 'wpdevart_booking_calendar' shortcode, specifically in versions up to and including 3.2.19. For exploitation to occur, a specific theme option known as 'delete_prev_date' must be enabled, thus facilitating an environment for authenticated attackers with contributor-level access or higher to inject additional SQL queries. These queries can potentially access sensitive data such as passwords from the database, putting user data at risk and compromising the overall integrity of the site.

Affected Version(s)

Booking calendar, Appointment Booking System * <= 3.2.19

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis
.