CVE-2023-3286: A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3286?
CVE-2023-3286 is considered to have a medium severity due to its potential for unauthorized user creation and data manipulation.
How do I fix CVE-2023-3286?
To fix CVE-2023-3286, update Easy!Appointments to version 1.5.0 or later to ensure that low privileged users cannot create other low privileged users.
What is the impact of CVE-2023-3286?
The impact of CVE-2023-3286 allows low privileged users to create additional low privileged users, leading to unauthorized access and manipulation of data.
Which versions of Easy!Appointments are affected by CVE-2023-3286?
CVE-2023-3286 affects all versions of Easy!Appointments prior to 1.5.0.
Who is affected by CVE-2023-3286?
Users of Easy!Appointments with low privileges are affected by CVE-2023-3286 as it allows them to escalate their privileges by creating new low privileged users.