The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/8a7bd9f6-2789-474b-a237-01c643fdfba7 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2023-01-02T21:49:16.234Z
Updated: 2023-01-10T09:08:27.832Z
Reserved: 2022-12-07T18:55:53.164Z
Link: CVE-2022-4340
JSON object: View
NVD Information
Status : Modified
Published: 2023-01-02T22:15:17.127
Modified: 2023-11-07T03:57:34.983
Link: CVE-2022-4340
JSON object: View
Redhat Information
No data.
CWE
No CWE.