RULE(RULE ID:324378)

Rule General Information
Release Date: 2020-03-17
Rule Name: Wordpress Plugin Appointment Booking Calendar Stored Cross Site Scripting Injection Vulnerability (CVE-2020-9371)
Severity:
CVE ID:
Rule Protection Details
Description: Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Others
Reference: http://packetstormsecurity.com/files/156694/WordPress-Appointment-Booking-Calendar-1.3.34-CSV-Injection.html
https://drive.google.com/open?id=1NNcYPaJir9SleyVr4cSPqpI2LNM7rtx9
https://wordpress.org/plugins/appointment-booking-calendar/#developers
https://wpvulndb.com/vulnerabilities/10110
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://wordpress.org/plugins/appointment-booking-calendar/#developers