CVE-2023-3289: A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3289?
CVE-2023-3289 is classified as a medium severity vulnerability due to its potential for unauthorized data manipulation.
How do I fix CVE-2023-3289?
To fix CVE-2023-3289, update Easy!Appointments to version 1.5.0 or later where the vulnerability is patched.
Who is affected by CVE-2023-3289?
CVE-2023-3289 affects versions of Easy!Appointments prior to 1.5.0, allowing low privileged users to exploit the system.
What type of vulnerability is CVE-2023-3289?
CVE-2023-3289 is a Broken Object Level Authorization (BOLA) vulnerability affecting service creation in Easy!Appointments.
Can CVE-2023-3289 lead to account compromise?
Yes, CVE-2023-3289 can lead to account compromise by allowing unauthorized users to manipulate services for any user, including admins.