Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-48831

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-48825

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48208

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
Attacker Value
Unknown

CVE-2023-48207

Disclosure Date: December 07, 2023 (last updated December 12, 2023)
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
Attacker Value
Unknown

CVE-2023-36133

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
Attacker Value
Unknown

CVE-2023-36132

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
Attacker Value
Unknown

CVE-2023-36131

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
Attacker Value
Unknown

CVE-2023-4110

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.