CVE-2022-0825: Amelia < 1.0.49 - Customer+ Arbitrary Appointments Status Update
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0825?
The severity of CVE-2022-0825 is considered high due to improper authorization allowing unauthorized access to sensitive booking information.
How do I fix CVE-2022-0825?
To fix CVE-2022-0825, update the Amelia WordPress plugin to version 1.0.49 or later.
What types of sensitive information can be accessed due to CVE-2022-0825?
CVE-2022-0825 allows unauthorized users to access sensitive booking information, including full names and phone numbers.
Who is affected by CVE-2022-0825?
All users of the Amelia WordPress plugin versions prior to 1.0.49 are affected by CVE-2022-0825.
What actions can unauthorized users take due to CVE-2022-0825?
Unauthorized users can update other customers' booking statuses and retrieve sensitive information related to bookings due to CVE-2022-0825.