V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-9372
CVE
HighConfirmedExploit available

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any bookin…

CVSS
7.8
High
EPSS
0.19
p95
Published
2020-01-01
Updated
2020-01-01
Description

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

Tags · CWE
CWE-1236
Affected products
Appointment_booking_calendar < 1.3.35
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.193 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
48204
exploitdb · https://www.exploit-db.com/exploits/48204
Enterprise
Affected software
ProductVendorStatus
appointment_booking_calendar*Tracked
Source databases
CVE