What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.
Explanation of Vulnerability in Simple Terms
The Booking and Rental Manager for Bike plugin contains a cross-site scripting (XSS) vulnerability that allows authenticated users with high privileges to inject malicious scripts. An attacker must have admin-level access and trick a site administrator into visiting a crafted page. The injected script executes in the admin's browser, potentially compromising site security or stealing sensitive data.
What an attacker can do
Inject malicious JavaScript that runs in an admin's browser session, potentially stealing credentials or modifying site content.
Potential impact on your site
A malicious admin or compromised admin account could inject scripts affecting other administrators or site functionality.
Conditions required to exploit
Admin-level access to the plugin, plus user interaction (admin must visit attacker-controlled page).
Key dates
External resources
Related vulnerabilities