Booking calendar, Appointment Booking System, CVE-2022-3982
- CVE, Research URL
- Application
- Published on
- Dec 12, 2022
- Research Description
- The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
- Affected versions
-
max 3.2.2.
- Status
-
vulnerable