Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-33564

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
Attacker Value
Unknown

CVE-2023-33563

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Attacker Value
Unknown

CVE-2023-33562

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2023-33561

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
Attacker Value
Unknown

CVE-2023-33560

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.