Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/175804 | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2023-12-07 07:15
Updated : 2023-12-11 15:22
NVD link : CVE-2023-48207
Mitre link : CVE-2023-48207
CVE.ORG link : CVE-2023-48207
JSON object : View
Products Affected
phpjabbers
- availability_booking_calendar
CWE
CWE-1236
Improper Neutralization of Formula Elements in a CSV File