Show filters
182 Total Results
Displaying 131-140 of 182
Sort by:
Attacker Value
Unknown
CVE-2021-37330
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another user/admin views the profile and clicks to view his avatar, an XSS will trigger.
0
Attacker Value
Unknown
CVE-2021-37333
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.
0
Attacker Value
Unknown
CVE-2020-21012
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
0
Attacker Value
Unknown
CVE-2021-24726
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
0
Attacker Value
Unknown
CVE-2020-25444
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.
0
Attacker Value
Unknown
CVE-2020-27379
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token is not being validated when the request is sent as a GET method. This results in an unauthorized change in the user's email ID, which can later be used to reset the password. The new password will be sent to a modified email ID.
0
Attacker Value
Unknown
CVE-2020-25445
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.
0
Attacker Value
Unknown
CVE-2021-24429
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.
0
Attacker Value
Unknown
CVE-2020-35382
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
0
Attacker Value
Unknown
CVE-2020-25889
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
0