ZeroHour

CVE-2022-0920

PoC
CVSS 3.1
7.5 high
EPSS
1%p72
Published
()
Modified
Description

The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data

Vendors
salonbookingsystem
Products
salon booking system
Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.