CVE-2022-1408

CVE-2022-1408: VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting

Vendor Unknown
Product VikBooking Hotel Booking Engine & PMS
Weakness CWE-79 · XSS
Published May 16, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Key dates

02Disclosure timeline

May 16, 2022 CVE published
August 3, 2024 Record updated