First published: Tue Jul 09 2024(Updated: )
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy!Appointments | <1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3290 has a medium severity rating due to its potential for unauthorized data manipulation.
To fix CVE-2023-3290, it is recommended to update Easy!Appointments to version 1.5.0 or later.
CVE-2023-3290 affects low privileged users who can create other low privileged users in the system.
CVE-2023-3290 is a Broken Object Level Authorization (BOLA) vulnerability.
CVE-2023-3290 allows unauthorized data manipulation by enabling the creation of low privileged user accounts.