Description
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43960 | A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation. |
References
| Link | Providers |
|---|---|
| https://github.com/alextselegidis/easyappointments |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-02T06:48:08.473Z
Reserved: 2023-06-15T23:55:48.796Z
Link: CVE-2023-3285
Updated: 2024-08-02T06:48:08.473Z
Status : Deferred
Published: 2024-07-09T10:15:02.380
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-3285
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD