CVE Published: 19/04/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: Patchstack |
Vendor: E4J s.r.l. |
Product: VikBooking Hotel Booking Engine & PMS (WordPress plugin) Status : PUBLISHED
CVE-2022-27863 Description
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N