Vulnerability Details CVE-2021-24429
The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-24429
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:-
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.0.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.0.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.0.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.0.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.0.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.2.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.3.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:1.3.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.0.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.1.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.1.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.2.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:2.3.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.1.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.10
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.10.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.11
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.11.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.12
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.13
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.13.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.14
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.14.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.14.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.14.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.15
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.16
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.16.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.17
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.17.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.18
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.18.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.19
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.19.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.2.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.20
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.20.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.21
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.22
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.22.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.22.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.23
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.24
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.24.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.25
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.26
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.26.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.26.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.27
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.27.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.28.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.28.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.28.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.3.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.30.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.30.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.30.7
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.31.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.32
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.32.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.32.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.32.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.32.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.34
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.34.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.34.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.36
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.36.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.36.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.36.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.36.7
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.37
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.37.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.37.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.39
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.42
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.42.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.42.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.43
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.43.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.44
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.44.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.44.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.44.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.7
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.8
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.8.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.8.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.9.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:3.9.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.3
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.8
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.4
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.7
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.8
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:4.9.9
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:5.0
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:5.1
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:5.2
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:5.5
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:5.6
-
cpe:2.3:a:salonbookingsystem:salon_booking_system:5.6.2