The Advanced Booking Calendar WordPress plugin prior to 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|