Sploitus

CVE-2024-2101

1 known exploit for CVE-2024-2101

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.

Affected products
Salon Booking System
Salonbookingsystem Salon Booking System
< 9.6.3
Fix
Available
CVSS 3.1
5.7 MEDIUM
EPSS
0.6% (48th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2024-04-17
CVE-2024-2101 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-2101

Proof-of-concept code and exploit modules indexed by Sploitus