Product:

Availability_booking_calendar

(Phpjabbers)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 8
Date Id Summary Products Score Patch Annotated
2023-08-03 CVE-2023-4110 A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Availability_booking_calendar 6.1
2023-08-04 CVE-2023-36131 PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. Availability_booking_calendar 9.8
2023-08-04 CVE-2023-36132 PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. Availability_booking_calendar 9.8
2023-08-04 CVE-2023-36133 PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. Availability_booking_calendar 9.8
2023-12-07 CVE-2023-48207 Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. Availability_booking_calendar 8.8
2023-12-07 CVE-2023-48208 A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php. Availability_booking_calendar 6.1
2023-12-07 CVE-2023-48825 Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. Availability_booking_calendar 5.4
2023-12-07 CVE-2023-48831 A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. Availability_booking_calendar 7.5