Phpjabbers
Phpjabbers Availability Booking Calendar: vulnerabilidades y CVE
Phpjabbers Availability Booking Calendar tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-48831 | Alta (7.5) | 1.2% | — | 7 dic 2023 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. |
| CVE-2023-48825 | Media (5.4) | 0.45% | — | 7 dic 2023 | Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. |
| CVE-2023-48208 | Media (6.1) | 0.50% | — | 7 dic 2023 | A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to… |
| CVE-2023-48207 | Alta (8.8) | 1.2% | — | 7 dic 2023 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. |
| CVE-2023-36133 | Crítica (9.8) | 0.89% | — | 4 ago 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. |
| CVE-2023-36132 | Crítica (9.8) | 0.89% | — | 4 ago 2023 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. |
| CVE-2023-36131 | Crítica (9.8) | 0.89% | — | 4 ago 2023 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. |
| CVE-2023-4110 | Media (6.1) | 1.8% | — | 3 ago 2023 | A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the… |