CVE · Medium

CVE-2023-49282 — Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.37

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-49282 Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.37 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.4 < 1.2.37 1.2.37 2023-12-05

CVE-2023-49282

The Amelia booking plugin versions before 1.2.37 contain a vulnerable version of the Microsoft Graph PHP SDK that includes test code exposing the phpInfo() function through a publicly accessible file. An attacker who can access the vendor directory would be able to execute phpInfo() and retrieve sensitive system information including configuration details, loaded modules, and environment variables. This exposure could enable attackers to obtain credentials or other secrets that facilitate further compromise of the application and its infrastructure.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.