What the vulnerability does
01Description
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
What the vulnerability does
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.
Explanation of Vulnerability in Simple Terms
BookingPress versions up to 1.0.74 contain an authentication bypass vulnerability. An attacker can bypass login checks and modify booking data or system settings without valid credentials. The vulnerability requires no user interaction and is remotely exploitable over the network. Site administrators should update immediately to a patched version.
What an attacker can do
Bypass authentication and modify bookings or site settings without a valid account.
Potential impact on your site
Attackers can alter bookings, cancel reservations, or change plugin settings without logging in.
Conditions required to exploit
Network access to the BookingPress installation; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities