CVE-2020-9372
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 8.61% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1236
- Affected
- codepeople/appointment booking calendar
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9Exploit, Third Party Advisory
- https://wordpress.org/plugins/appointment-booking-calendar/#developersRelease Notes, Third Party Advisory
- https://www.hotdreamweaver.com/support/view.php?id=815925Permissions Required
- http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9Exploit, Third Party Advisory
- https://wordpress.org/plugins/appointment-booking-calendar/#developersRelease Notes, Third Party Advisory
- https://www.hotdreamweaver.com/support/view.php?id=815925Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.