What the vulnerability does
01Description
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
Explanation of Vulnerability in Simple Terms
BookIt versions up to 2.4.0 contain a vulnerability that allows an attacker to modify data or disrupt service without authentication. The flaw stems from insufficient input validation or access controls. Site administrators should update to version 2.5.5 or later to resolve the issue.
What an attacker can do
Modify site data or cause temporary service disruption without logging in.
Potential impact on your site
Unauthorized changes to event bookings or availability, or temporary service interruptions.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities