Sploitus

CVE-2024-2102

1 known exploit for CVE-2024-2102

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field and 'sms_prefix' parameter when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Bookings' page and the malicious script is executed in the admin context.

Affected products
Salon Booking System
Salonbookingsystem Salon Booking System
< 9.6.3
Fix
Available
CVSS 3.1
4.7 MEDIUM
EPSS
0.5% (39th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2024-04-17
CVE-2024-2102 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-2102

Proof-of-concept code and exploit modules indexed by Sploitus