Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2022-1407
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-27863
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
0
Attacker Value
Unknown
CVE-2022-27862
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
0
Attacker Value
Unknown
CVE-2018-17842
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
0