The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-06-26T06:00:04.151Z
Updated: 2024-10-28T20:13:18.059Z
Reserved: 2024-05-17T14:55:43.858Z
Link: CVE-2024-5071
Vulnrichment
Updated: 2024-08-01T21:03:10.655Z
NVD
Status : Awaiting Analysis
Published: 2024-06-26T06:15:16.463
Modified: 2024-11-21T09:46:54.120
Link: CVE-2024-5071
Redhat
No data.