Description
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43964 | A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation. |
References
| Link | Providers |
|---|---|
| https://github.com/alextselegidis/easyappointments |
|
History
Mon, 26 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Easyappointments
Easyappointments easyappointments |
|
| CPEs | cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Easyappointments
Easyappointments easyappointments |
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-02T06:48:08.585Z
Reserved: 2023-06-15T23:55:52.520Z
Link: CVE-2023-3289
Updated: 2024-08-02T06:48:08.585Z
Status : Modified
Published: 2024-07-09T11:15:12.787
Modified: 2024-11-21T08:16:56.233
Link: CVE-2023-3289
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD