VendorsPHPJabberstime_slots_booking_calendar3.3
Vulnerabilities

PHPJabbers Time Slots Booking Calendar 3.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-33561
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
Published 2023-08-01 · Modified
9.8EPSS 0.010
CVE-2023-33562
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Published 2023-08-01 · Modified
9.8EPSS 0.008
CVE-2023-33563
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Published 2023-08-01 · Modified
8.8EPSS 0.008
CVE-2023-33560
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
Published 2023-08-01 · Modified
6.1EPSS 0.005
CVE-2023-33564
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
Published 2023-08-01 · Modified
6.1EPSS 0.005