Back

HIGH

A BOLA vulnerability in POST /appointments in EasyAppointments < 1.5.0

Published Jul 9, 2024

Description

A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner palo_alto
Published Jul 9, 2024
Updated Aug 2, 2024
Reserved Jun 15, 2023

CISA Vulnrichment

Updated Jul 31, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner palo_alto
Published Jul 9, 2024
Updated Aug 2, 2024

GitHub

No data