Sploitus

CVE-2022-0919

1 known exploit for CVE-2022-0919

The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.

Salonbookingsystem Salon Booking System
< 7.6.3
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
1.2% (65th percentile)
Weakness
CWE-862
NVD status
Modified
Published
2022-04-11
CVE-2022-0919 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-0919

Proof-of-concept code and exploit modules indexed by Sploitus