CVE-2022-1408
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected products
- Vikbooking Hotel Booking Engine & Pms
- Vikwp Hotel Booking Engine \& Pms
- < 1.5.8
- Fix
- Available
- CVSS 3.1
- 4.8 MEDIUM
- EPSS
- 0.6% (45th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-05-16
CVE-2022-1408 at NVD
1 known exploit for CVE-2022-1408
Proof-of-concept code and exploit modules indexed by Sploitus