CVE-2023-3700: Authorization Bypass Through User-Controlled Key in alextselegidis/easyappointments
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Other sources
Easy!Appointments 1.4.3 and prior has an Improper Access Control vulnerability. This issue is patched at commit b37b46019553089db4f22eb2fe998bca84b2cb64 and anticipated to be part of version 1.5.0.
Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/alextselegidis/easyappointmentsto a version that resolves this vulnerability.Fixed in 1.5.0 - Upgrade
Upgrade
alextselegidis/easyappointmentsto a version that resolves this vulnerability.Fixed in 1.5.0Patch b37b46019553089db4f22eb2fe998bca84b2cb64
Event History
Frequently Asked Questions
What is CVE-2023-3700?
CVE-2023-3700 is an Improper Access Control vulnerability in the GitHub repository alextselegidis/easyappointments prior to version 1.5.0.
How severe is CVE-2023-3700?
CVE-2023-3700 has a severity score of 6.3, which is considered medium.
What software versions are affected by CVE-2023-3700?
Easy!Appointments versions prior to 1.5.0 and alextselegidis/easyappointments versions up to and including 1.4.3 are affected by CVE-2023-3700.
How can I fix CVE-2023-3700?
To fix CVE-2023-3700, you should update to version 1.5.0 of Easy!Appointments or alextselegidis/easyappointments.
Where can I find more information about CVE-2023-3700?
You can find more information about CVE-2023-3700 at the following references: [huntr.dev](https://huntr.dev/bounties/e8d530db-a6a7-4f79-a95d-b77654cc04f8), [GitHub commit](https://github.com/alextselegidis/easyappointments/commit/b37b46019553089db4f22eb2fe998bca84b2cb64), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-3700).