cleantalk
Vulnerabilities and Security Researches

Appointment Booking Calendar, CVE-2015-7319

CVE, Research URL

CVE-2015-7319

Published on
Sep 30, 2015
Research Description
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
Affected versions
max 1.1.8.
Status
vulnerable