Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.
References
Configurations
History
21 Nov 2024, 05:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://medium.com/%40singh.satyam158/vulnerabilities-in-booking-core-1-7-d85d1dfae44e - |
07 Nov 2023, 03:20
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-07-14 15:15
Updated : 2024-11-21 05:17
NVD link : CVE-2020-25444
Mitre link : CVE-2020-25444
CVE.ORG link : CVE-2020-25444
JSON object : View
Products Affected
bookingcore
- booking_core
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')