Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering
The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
References
-
https://wpscan.com/vulnerability/fbbfa907-3efd-4050-9651-d3836af062a9/ technical-descriptionvdb-entryexploit
Affected products
Salon Booking System
- =<10.30.33