MEDIUM🇵🇱 Wersja polska

CVE-2023-51296

CVSS 6.1v3.1pub. 2025-02-19upd. 2025-11-04

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Phpjabbers Event Booking Calendar

    APP
    Phpjabbers
    4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2023-40765CRITICAL9.8PL ✓same product

User enumeration w PHPJabbers Event Booking Calendar v4.0

CVE-2023-51293HIGH7.5same product

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calenda...

CVE-2014-10015HIGH7.5same product

SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attack...

CVE-2023-51295MEDIUM6.5same product

PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_k...

CVE-2023-51298MEDIUM4.7same product

PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker t...