First published: Tue Jul 09 2024(Updated: )
A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy!Appointments | <1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3288 is classified as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2023-3288, update Easy!Appointments to version 1.5.0 or later.
CVE-2023-3288 is a broken object level authorization (BOLA) vulnerability.
Users of Easy!Appointments versions prior to 1.5.0 are affected by CVE-2023-3288.
CVE-2023-3288 allows low privileged users to create privileged users, potentially leading to unauthorized access or manipulation of the system.