CVE-2023-0768
08.05.2023, 14:15
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.Enginsight
Vendor | Product | Version |
---|---|---|
avirato | hotels_online_booking_engine | 𝑥 ≤ 5.0.5 |
𝑥
= Vulnerable software versions