CPE
An unauthenticated SQL injection vulnerability in the LatePoint Appointment Booking Plugin allows remote attackers to extract sensitive database information via the booking[service_id] parameter.