Path Traversal Vulnerability Affects Salon Booking System
CVE-2024-37231

8.6HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
24 June 2024

Summary

The Salon Booking System is affected by a Path Traversal vulnerability that allows attackers to manipulate sensitive files within restricted directories. This flaw enables unauthorized access to the filesystem, leading to potential data breaches. Versions from n/a through 9.9 are impacted, creating an urgent need for remediation to protect sensitive information and ensure the integrity of the application. Users must apply security patches and adopt best practices to mitigate risks associated with this vulnerability.

Affected Version(s)

Salon booking system <= 9.9

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.