Known Vulnerabilities for Booking Core by Bookingcore
Listed below are 6 of the newest known vulnerabilities associated with "Booking Core" by "Bookingcore".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-37333 json | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/use... | 9.8 - CRITICAL | 2021-10-04 | 2021-10-12 |
| CVE-2021-37331 json | Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading... | 5.3 - MEDIUM | 2021-10-04 | 2022-07-12 |
| CVE-2021-37330 json | Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile sect... | 5.4 - MEDIUM | 2021-10-04 | 2021-10-12 |
| CVE-2020-27379 json | Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token... | 6.5 - MEDIUM | 2021-07-14 | 2023-11-07 |
| CVE-2020-25445 json | The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input c... | 7.8 - HIGH | 2021-07-14 | 2023-11-07 |
| CVE-2020-25444 json | Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Your... | 5.4 - MEDIUM | 2021-07-14 | 2023-11-07 |