6.1
CVSSv3

CVE-2023-48208

Published: 07/12/2023 Updated: 09/12/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an malicious user to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpjabbers availability booking calendar 5.0

Exploits

PHPJabbers Availability Booking Calendar version 50 suffers from multiple cross site scripting vulnerabilities ...