The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.3. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tmsproducts
Tmsproducts amelia |
|
CPEs | cpe:2.3:a:tmsproducts:amelia:*:*:*:*:lite:wordpress:*:* cpe:2.3:a:tmsproducts:amelia:*:*:*:*:premium:wordpress:*:* |
|
Vendors & Products |
Tmsproducts
Tmsproducts amelia |
Thu, 05 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 05 Sep 2024 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.3. This makes it possible for unauthenticated attackers to access employee calendar details, including Google Calendar OAuth tokens in the premium version. | |
Title | Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.3 - Missing Authorization to Sensitive Information Exposure | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-05T09:29:48.753Z
Updated: 2024-09-05T19:38:14.016Z
Reserved: 2024-06-25T17:38:01.385Z
Link: CVE-2024-6332
Vulnrichment
Updated: 2024-09-05T19:38:07.227Z
NVD
Status : Analyzed
Published: 2024-09-05T10:15:02.970
Modified: 2024-09-12T12:45:37.917
Link: CVE-2024-6332
Redhat
No data.