Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2023-48831
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
0
Attacker Value
Unknown
CVE-2023-48825
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
0
Attacker Value
Unknown
CVE-2023-48208
Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
0
Attacker Value
Unknown
CVE-2023-48207
Disclosure Date: December 07, 2023 (last updated December 12, 2023)
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
0
Attacker Value
Unknown
CVE-2023-36133
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
0
Attacker Value
Unknown
CVE-2023-36132
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2023-36131
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
0
Attacker Value
Unknown
CVE-2023-4110
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0