CVE-2023-38520
MEDIUMPINPOINT.WORLD Pinpoint Booking System <2.9.9.3.4 - XSS
Title source: llmDescription
External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.
Scores
CVSS v3
6.5
EPSS
0.0021
EPSS Percentile
42.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Classification
CWE
CWE-472
Status
draft
Timeline
Published
Jun 04, 2024
Tracked Since
Feb 18, 2026