6.1
CVSSv3

CVE-2021-24429

Published: 12/07/2021 Updated: 15/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Salon booking system WordPress plugin prior to 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

salonbookingsystem salon booking system

Github Repositories

CVE-Collection By Phu Tran Wordpress Plugins CVEs CVE-2021-24429 CVE-2021-24455 CVE-2021-24443 CVE-2021-24379