Skip to main content

Vendor/product archive

bookingcore / booking_core CVEs

Beta · best-effort

6 CVEs tagged to bookingcore / booking_core1 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2021-37333

Published Oct 4, 2021

Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a sessio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37331

Published Oct 4, 2021

Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37330

Published Oct 4, 2021

Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27379

Published Jul 14, 2021

Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token is not being validated when the request is sent as a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25445

Published Jul 14, 2021

The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25444

Published Jul 14, 2021

Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hote…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1