CVE-2023-38051: A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38051?
CVE-2023-38051 is considered a moderate severity vulnerability due to the potential for unauthorized data manipulation.
How do I fix CVE-2023-38051?
To fix CVE-2023-38051, update Easy!Appointments to version 1.5.0 or later, which addresses the vulnerability.
What type of vulnerability is CVE-2023-38051?
CVE-2023-38051 is a Broken Object Level Authorization (BOLA) vulnerability affecting user operations.
Who is affected by CVE-2023-38051?
CVE-2023-38051 affects low privileged users who are able to access, modify, or delete information meant for other low privileged users.
What are the potential consequences of CVE-2023-38051?
The potential consequences of CVE-2023-38051 include unauthorized access to sensitive data and unauthorized modification or deletion of user records.