Show filters
90 Total Results
Displaying 11-20 of 90
Sort by:
Attacker Value
Unknown

CVE-2023-48830

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
Attacker Value
Unknown

CVE-2023-48828

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48827

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48826

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
Attacker Value
Unknown

CVE-2023-48825

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48208

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
Attacker Value
Unknown

CVE-2023-48207

Disclosure Date: December 07, 2023 (last updated December 12, 2023)
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
Attacker Value
Unknown

CVE-2023-48172

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
Attacker Value
Unknown

CVE-2023-43147

Disclosure Date: October 12, 2023 (last updated October 19, 2023)
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
Attacker Value
Unknown

CVE-2023-36127

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.