CVE-2023-48833 – PHPJabbers Time Slots Booking Calendar 4.0 Missing Rate Limiting
https://notcve.org/view.php?id=CVE-2023-48833
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. La falta de limitación de velocidad en pjActionAJaxSend en Time Slots Booking Calendar 4.0 permite a los atacantes provocar el agotamiento de los recursos. PHPJabbers Time Slots Booking Calendar version 4.0 suffers from a missing rate limiting control that can allow for resource exhaustion. • http://packetstormsecurity.com/files/176042 https://www.phpjabbers.com/time-slots-booking-calendar • CWE-400: Uncontrolled Resource Consumption •
CVE-2023-48828 – PHPJabbers Time Slots Booking Calendar 4.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2023-48828
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. Time Slots Booking Calendar 4.0 es vulnerable a problemas de Múltiple Coss-Site Scripting (XSS) Almacenado a través del nombre, plugin_sms_api_key, plugin_sms_country_code, calendar_id, título, nombre de país o parámetro customer_name. PHPJabbers Time Slots Booking Calendar version 4.0 suffers from multiple persistent cross site scripting vulnerabilities. • http://packetstormsecurity.com/files/176037 https://www.phpjabbers.com/time-slots-booking-calendar • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-48827 – PHPJabbers Time Slots Booking Calendar 4.0 HTML Injection
https://notcve.org/view.php?id=CVE-2023-48827
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. Time Slots Booking Calendar 4.0 es vulnerable a múltiples problemas de inyección de HTML a través del nombre, plugin_sms_api_key, plugin_sms_country_code, calendar_id, título, nombre de país o parámetro customer_name. PHPJabbers Time Slots Booking Calendar version 4.0 suffers from an html injection vulnerability. • http://packetstormsecurity.com/files/176036 https://www.phpjabbers.com/time-slots-booking-calendar • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-48826 – PHPJabbers Time Slots Booking Calendar 4.0 CSV Injection
https://notcve.org/view.php?id=CVE-2023-48826
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. Time Slots Booking Calendar 4.0 es vulnerable a la inyección de CSV a través del campo de ID único de la Lista de reservas. PHPJabbers Time Slots Booking Calendar version 4.0 suffers from a CSV injection vulnerability. • http://packetstormsecurity.com/files/176034 https://www.phpjabbers.com/time-slots-booking-calendar • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2023-33561
https://notcve.org/view.php?id=CVE-2023-33561
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords. La validación incorrecta del parámetro de contraseña en Time Slots Booking Calendar v 3.3 de PHPJabbers resulta en contraseñas inseguras. • https://medium.com/%40bcksec/multiple-vulnerabilities-in-php-jabbers-scripts-25af4afcadd4 https://www.phpjabbers.com/time-slots-booking-calendar •