Extension WordPress
Vulnérabilités Advanced Booking Calendar
Cette page rassemble les failles publiées pour Advanced Booking Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced Booking Calendar
8 fiches
Advanced Booking Calendar <= 1.7.1 – Unauthenticated SQL Injection
The Advanced Booking Calendar for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-1.7.1
Non indiqué
02/12/2022
Advanced Booking Calendar <= 1.7.1 – Cross Site Request Forgery
The Advanced Booking Calendar for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for…
*-1.7.1
Non indiqué
01/12/2022
Advanced Booking Calendar <= 1.7.0 – Authenticated SQL Injection
The Advanced Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 1.7.1)
1.7.1
21/03/2022
Advanced Booking Calendar <= 1.7.0 – Reflected Cross-Site Scripting
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
*-1.7.0
1.7.1
21/03/2022
Advanced Booking Calendar <= 1.6.9 – Unauthenticated SQL Injection
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an…
*-1.6.9
1.7.0
28/02/2022
Advanced Booking Calendar <= 1.6.7 – Reflected Cross-Site Scripting
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue
[*, 1.6.8)
1.6.8
30/03/2021
Advanced Booking Calendar <= 1.6.6 – Reflected Cross-Site Scripting via calId Parameter
The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
[*, 1.6.7)
1.6.7
28/03/2021
Advanced Booking Calendar <= 1.6.1 – Unauthenticated SQL Injection
The Advanced Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘calendarId’ parameter in versions up to, and including, 1.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
[*, 1.6.2)
1.6.2
22/10/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.