CVE-2023-3285: A BOLA vulnerability in POST /appointments in EasyAppointments < 1.5.0
Published Jul 9, 2024
·Updated
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.
Affected Software
1 affected component
EasyAppointments EasyAppointments<1.5.0
Event History
Jul 9, 2024
CVE Published
via MITRE·09:37 AM
Data Sourced
via MITRE·09:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-3285?
CVE-2023-3285 is categorized as a high severity vulnerability due to its potential for unauthorized data manipulation.
2
How do I fix CVE-2023-3285?
To fix CVE-2023-3285, update EasyAppointments to version 1.5.0 or later.
3
What kind of attack does CVE-2023-3285 enable?
CVE-2023-3285 enables low privileged users to create appointments for any user, including administrators.
4
Which versions of EasyAppointments are affected by CVE-2023-3285?
EasyAppointments versions prior to 1.5.0 are vulnerable to CVE-2023-3285.
5
Who is impacted by CVE-2023-3285?
Any user of EasyAppointments who has insufficient privileges may exploit CVE-2023-3285 to manipulate appointments.