First published: Tue Jul 09 2024(Updated: )
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy!Appointments | <1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3289 is classified as a medium severity vulnerability due to its potential for unauthorized data manipulation.
To fix CVE-2023-3289, update Easy!Appointments to version 1.5.0 or later where the vulnerability is patched.
CVE-2023-3289 affects versions of Easy!Appointments prior to 1.5.0, allowing low privileged users to exploit the system.
CVE-2023-3289 is a Broken Object Level Authorization (BOLA) vulnerability affecting service creation in Easy!Appointments.
Yes, CVE-2023-3289 can lead to account compromise by allowing unauthorized users to manipulate services for any user, including admins.