The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
History

Mon, 14 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Salonbookingsystem
Salonbookingsystem salon Booking System
Weaknesses CWE-352
CPEs cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:*
Vendors & Products Salonbookingsystem
Salonbookingsystem salon Booking System

Fri, 09 Aug 2024 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-09T20:00:15.839Z

Reserved: 2024-03-13T15:38:04.813Z

Link: CVE-2024-2429

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.535Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-26T05:15:50.083

Modified: 2025-04-14T14:18:25.260

Link: CVE-2024-2429

cve-icon Redhat

No data.