Vulnerability Description
Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Classroombookings | Classroombookings | 2.6.4 |
Related Weaknesses (CWE)
References
- https://gist.github.com/enferas/bd8ec37999c216eceabd6b80d5a95f94ExploitThird Party Advisory
- https://github.com/craigrodway/classroombookings/issues/52ExploitIssue TrackingThird Party Advisory
- https://gist.github.com/enferas/bd8ec37999c216eceabd6b80d5a95f94ExploitThird Party Advisory
- https://github.com/craigrodway/classroombookings/issues/52ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2023-23012?
CVE-2023-23012 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php.
How severe is CVE-2023-23012?
CVE-2023-23012 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23012?
Check the references section above for vendor advisories and patch information. Affected products include: Classroombookings Classroombookings.