Showing 2 vulnerabilities on this page for salon_booking_system

Signals CISA KEV Ransomware Nuclei
salon_booking_system vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerability

Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.

CWE-269May 17, 2024
CVSS6.8v3.1EPSS0.524%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Salon booking system <= 9.6.5 - Editor+ Stored XSS via Email Settings

The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CWE-79Apr 26, 2024
CVSS6.3v3.1EPSS0.465%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX