CVE Database
/

CVE-2022-1932

Back to search

CVE-2022-1932

Published: Aug 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file

VendorProductVersions

Unknown

Rezgo Online Booking

affected
4.1.8 - < 4.1.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now