First published: Tue Jul 09 2024(Updated: )
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy!Appointments | <1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3286 is considered to have a medium severity due to its potential for unauthorized user creation and data manipulation.
To fix CVE-2023-3286, update Easy!Appointments to version 1.5.0 or later to ensure that low privileged users cannot create other low privileged users.
The impact of CVE-2023-3286 allows low privileged users to create additional low privileged users, leading to unauthorized access and manipulation of data.
CVE-2023-3286 affects all versions of Easy!Appointments prior to 1.5.0.
Users of Easy!Appointments with low privileges are affected by CVE-2023-3286 as it allows them to escalate their privileges by creating new low privileged users.