Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2022-1407

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack
Attacker Value
Unknown

CVE-2022-27863

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
Attacker Value
Unknown

CVE-2022-27862

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
Attacker Value
Unknown

CVE-2018-17842

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.