CVE-2023-3290: A BOLA vulnerability in POST /customers in EasyAppointments < 1.5.0
Published Jul 9, 2024
·Updated
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
Affected Software
1 affected component
EasyAppointments EasyAppointments<1.5.0
Event History
Jul 9, 2024
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-3290?
CVE-2023-3290 has a medium severity rating due to its potential for unauthorized data manipulation.
2
How do I fix CVE-2023-3290?
To fix CVE-2023-3290, it is recommended to update Easy!Appointments to version 1.5.0 or later.
3
What types of users are affected by CVE-2023-3290?
CVE-2023-3290 affects low privileged users who can create other low privileged users in the system.
4
What kind of vulnerability is CVE-2023-3290?
CVE-2023-3290 is a Broken Object Level Authorization (BOLA) vulnerability.
5
What is the impact of CVE-2023-3290 on the system?
CVE-2023-3290 allows unauthorized data manipulation by enabling the creation of low privileged user accounts.