Show filters
182 Total Results
Displaying 121-130 of 182
Sort by:
Attacker Value
Unknown
CVE-2022-28115
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
0
Attacker Value
Unknown
CVE-2021-25061
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
0
Attacker Value
Unknown
CVE-2021-45003
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.
0
Attacker Value
Unknown
CVE-2021-25040
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-24930
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-24645
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-24646
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-42663
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.
0
Attacker Value
Unknown
CVE-2021-42662
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
0
Attacker Value
Unknown
CVE-2021-37331
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL.
0