First published: Sat Apr 15 2023(Updated: )
Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Easy!Appointments | <1.5.0 |
https://github.com/alextselegidis/easyappointments/commit/75b24735767868344193fb2cc56e17ee4b9ac4be
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2104 is a vulnerability that allows improper access control in GitHub repository alextselegidis/easyappointments prior to version 1.5.0.
The severity of CVE-2023-2104 is medium with a CVSS score of 5.4.
CVE-2023-2104 allows unauthorized access to the Easyappointments Easyappointments repository prior to version 1.5.0.
To fix CVE-2023-2104, update Easyappointments Easyappointments to version 1.5.0 or later.
More information about CVE-2023-2104 can be found at the following references: [GitHub Commit](https://github.com/alextselegidis/easyappointments/commit/75b24735767868344193fb2cc56e17ee4b9ac4be), [Huntr Dev](https://huntr.dev/bounties/3099b8d1-c49c-41b8-a929-73ccded6fc7c).