Skip to main content

Vendor/product archive

twinkletoessoftware / booked CVEs

Beta · best-effort

3 CVEs tagged to twinkletoessoftware / booked0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-24058

Published Jan 22, 2023

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version fr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30706

Published Jul 26, 2022

Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by h…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9581

Published Mar 6, 2019

phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1