CRITICAL🇵🇱 Wersja polska

CVE-2023-38050

CVSS 9.1v3.1pub. 2024-07-09upd. 2024-11-21

A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

🤖 AI Analysis
How it works

The vulnerability affects the API endpoints: GET, PUT, and DELETE /webhooks/{webhookId}. The application does not properly verify whether the requesting user is the owner of the resource identified by the webhookId parameter. An attacker with low privilege level can therefore provide the identifier of a webhook belonging to another user (including an administrator) and perform any read, edit, or delete operation on it.

Impact

An attacker can read confidential webhook configuration data of other users, modify it (e.g., redirect notifications to an address controlled by the attacker), or permanently delete it, leading to unauthorized data access and unauthorized manipulation of system configuration.

Mitigation & patch

Apply patches available from the vendor according to the references. It is recommended to monitor the project repository at https://github.com/alextselegidis/easyappointments for information about available updates.

Who is affected

EasyAppointments application (alextselegidis/easyappointments) — specific versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Easyappointments

    APP
    Easyappointments
    < 1.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-57602CRITICAL9.8PL ✓same product

EasyAppointments v.1.5.0 — privilege escalation przez index.php

CVE-2023-38051CRITICAL9.9PL ✓same product

BOLA w Easy!Appointments — nieuprawniony dostęp do danych sekretarek

CVE-2023-38048CRITICAL9.9PL ✓same product

BOLA w Easy!Appointments — nieautoryzowany dostęp do kont dostawców

CVE-2023-3287CRITICAL9.9PL ✓same product

BOLA w Easy!Appointments — privilege escalation do administratora

CVE-2023-38049CRITICAL9.9PL ✓same product

BOLA w EasyAppointments — nieuprawniony dostęp do wizyt innych użytkowników