nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24429 CVE-2021-24429
MEDIUM
Salon Booking System < 6.3.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
Record summary
CVE-2021-24429 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Salon booking systemBrowse Salon Booking System / Salon booking system | CVE List | 6.3.1 to < 6.3.1 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24429Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2021-24429Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.comConfirmation
https://wpscan.com/vulnerability/e922b788-7da5-43b4-9b05-839c8610252a