S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 10, 2024

CVE-2023-4110 Scanner

Detects 'Cross-Site Scripting' vulnerability in PHPJabbers Availability Booking Calendar affects v. 5.0

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-4110
6.1
CVSSlow
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235957 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
Availability Booking Calendarby PHP Jabbers
5.0
availability_booking_calendarby phpjabbers
5.0
Updated Aug 22, 2026View on NVD →
Detail

The PHPJabbers Availability Booking Calendar is a versatile software solution used primarily by hospitality businesses like hotels, rental services, and event planners to manage bookings and availability online. It integrates seamlessly into existing websites, providing an intuitive interface for both business owners and customers. This calendar application allows users to customize booking forms, manage reservations, set availability, and process payments, making it an essential tool for businesses looking to streamline their booking processes and enhance customer service.

The detected vulnerability involves a Cross-Site Scripting (XSS) issue within the PHPJabbers Availability Booking Calendar. XSS vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users, leading to unauthorized access to user sessions and sensitive information. This specific issue arises due to improper validation of user-supplied input in the 'session_id' parameter, making it possible for attackers to execute arbitrary web scripts in the context of the user's browser session.

The vulnerability exists within the '/index.php' file, where the 'session_id' parameter fails to properly sanitize input before incorporating it into the output it generates. By crafting a malicious URL containing a script in the 'session_id' parameter, an attacker can trigger the vulnerability, leading to the execution of the script whenever a user visits the manipulated URL. This flaw can result in unauthorized actions being performed on behalf of the user, theft of session cookies, and other potentially damaging outcomes.

If exploited, the XSS vulnerability in the PHPJabbers Availability Booking Calendar could lead to several adverse effects, including theft of user credentials, hijacking of user sessions, redirecting users to malicious sites, and the execution of unwanted actions in the context of the user's session. This can severely compromise user privacy and security, erode trust in the affected platform, and potentially expose the platform to further attacks.

By leveraging the security scanning capabilities of S4E, businesses can identify and mitigate vulnerabilities like the Cross-Site Scripting issue in the PHPJabbers Availability Booking Calendar. Our platform offers comprehensive scanning that uncovers potential security flaws, helping to safeguard digital assets against cyber threats. Joining S4E provides access to expert analyses, timely vulnerability detections, and actionable recommendations, ensuring your online presence remains secure and trustworthy.

 

References

Solution Advice
  1. Validate and sanitize all user-supplied input to ensure that it does not contain potentially malicious content.
  2. Implement content security policies that restrict the execution of unauthorized scripts.
  3. Use secure coding practices to encode or escape user-generated content before displaying it in a web browser.
  4. Regularly update and patch third-party components to address known vulnerabilities.
  5. Conduct regular security assessments and penetration testing to identify and remediate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-4110 scanner - Cross-Site Scripting vulnerability in PHPJabbers Availability Booking Calendar | S4E