A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
The vulnerability affects the API endpoints: GET, PUT, and DELETE /webhooks/{webhookId}. The application does not properly verify whether the requesting user is the owner of the resource identified by the webhookId parameter. An attacker with low privilege level can therefore provide the identifier of a webhook belonging to another user (including an administrator) and perform any read, edit, or delete operation on it.
An attacker can read confidential webhook configuration data of other users, modify it (e.g., redirect notifications to an address controlled by the attacker), or permanently delete it, leading to unauthorized data access and unauthorized manipulation of system configuration.
Apply patches available from the vendor according to the references. It is recommended to monitor the project repository at https://github.com/alextselegidis/easyappointments for information about available updates.
EasyAppointments application (alextselegidis/easyappointments) — specific versions indicated in the vendor's references
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LEasyappointments
APPEasyappointments< 1.5.0
Related vulnerabilities
EasyAppointments v.1.5.0 — privilege escalation przez index.php
BOLA w Easy!Appointments — nieuprawniony dostęp do danych sekretarek
BOLA w Easy!Appointments — nieautoryzowany dostęp do kont dostawców
BOLA w Easy!Appointments — privilege escalation do administratora
BOLA w EasyAppointments — nieuprawniony dostęp do wizyt innych użytkowników