CVE-2021-24232
EUVD-2021-1114622.04.2021, 21:15
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elbtide | advanced_booking_calendar | 𝑥 < 1.6.8 |
𝑥
= Vulnerable software versions