CVE-2021-25040 – Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25040
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting El plugin Booking Calendar de WordPress versiones anteriores a 8.9.2, no sanea y escapa del parámetro booking_type antes de devolverlo a una página de administración, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/3ed821a6-c3e2-4964-86f8-d14c4a54708a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-10363 – Booking calendar, Appointment Booking System < 2.2.3 - Unauthenticated Parameter Manipulation
https://notcve.org/view.php?id=CVE-2018-10363
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices. Se ha descubierto un problema en el plugin de WpDevArt "Booking calendar, Appointment Booking System" 2.2.2 para WordPress. Múltiples parámetros permiten que los atacantes remotos manipulen los valores para que cambien datos como los precios. An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin in versions up to, and including, 2.2.2 for WordPress. • https://gist.github.com/B0UG/68d3161af0c0ec85c615ca7452f9755e • CWE-20: Improper Input Validation •
CVE-2017-2151
https://notcve.org/view.php?id=CVE-2017-2151
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Booking Calendar versiones 7.1 y anteriores, que permitiría a un atacante remoto inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://jvn.jp/en/jp/JVN54762089/index.html http://wpbookingcalendar.com/changelog • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-2150
https://notcve.org/view.php?id=CVE-2017-2150
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. Vulnerabilidad de salto de directorio en Booking Calendar versioes 7.0 y anteriores, que permitiría a un atacante remoto leer ficheros arbitrarios a través de un parámetro captcha_chalange especialmente manipulado. • http://jvn.jp/en/jp/JVN18739672/index.html http://wpbookingcalendar.com/changelog • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •