Description
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43960 | A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation. |
References
| Link | Providers |
|---|---|
| https://github.com/alextselegidis/easyappointments |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-02T06:48:08.473Z
Reserved: 2023-06-15T23:55:48.796Z
Link: CVE-2023-3285
Updated: 2024-08-02T06:48:08.473Z
Status : Awaiting Analysis
Published: 2024-07-09T10:15:02.380
Modified: 2024-11-21T08:16:55.633
Link: CVE-2023-3285
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD