CVE Database /
CVE-2015-9299
CVE · Medium
CVE-2015-9299 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2015-9299
|
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 5.5.7.1
|
5.5.7.1 |
2015-06-04 |
—
|
CVE-2015-9299
The Events Manager plugin before version 5.5.7.1 contains a DOM-based cross-site scripting vulnerability that can be exploited through the dbem_event_reapproved_email_body parameter. An attacker could inject malicious scripts via this parameter, which would execute in users' browsers when the affected code is processed. This vulnerability affects all versions prior to 5.5.7.1 and was resolved in that release.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings