ZeroHour

CVE-2022-1006

PoC
CVSS 3.1
7.2 high
EPSS
1%p73
Published
()
Modified
Description

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

Vendors
elbtide
Products
advanced booking calendar
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.