CVE-2023-38047: A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38047?
CVE-2023-38047 is considered to have a high severity due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2023-38047?
To fix CVE-2023-38047, update Easy!Appointments to version 1.5.0 or later to mitigate the vulnerability.
Who is affected by CVE-2023-38047?
CVE-2023-38047 affects users of Easy!Appointments versions prior to 1.5.0, allowing low privileged users to access and manipulate categories.
What types of operations are vulnerable in CVE-2023-38047?
CVE-2023-38047 exploits vulnerabilities in GET, PUT, and DELETE operations for categories, leading to unauthorized actions.
What could be the consequences of CVE-2023-38047?
The consequences of CVE-2023-38047 include unauthorized access to sensitive data and potential disruption of services due to data manipulation.