Security Advisory

CVE-2023-1977

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-08-16 11:03:28
Last updated 2024-10-08 19:08:16
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.