salon_booking_system Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with salon_booking_system products.
Products
- salon_booking_system2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-48319MEDIUM | WordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerabilityImproper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6. CWE-269May 17, 2024 | CVSS6.8v3.1 | EPSS0.524% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2603MEDIUM | Salon booking system <= 9.6.5 - Editor+ Stored XSS via Email SettingsThe Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) CWE-79Apr 26, 2024 | CVSS6.3v3.1 | EPSS0.465% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |