CVE-2023-38052: A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38052?
CVE-2023-38052 is considered to be of high severity due to the potential for unauthorized access and data manipulation by low privileged users.
How do I fix CVE-2023-38052?
To fix CVE-2023-38052, ensure proper access controls are implemented to validate user permissions before allowing access to admin endpoints.
What types of attacks does CVE-2023-38052 enable?
CVE-2023-38052 enables unauthorized access, data modification, and deletion by allowing low privileged users to act on behalf of high privileged users.
Which versions of Easy!Appointments are affected by CVE-2023-38052?
All versions of Easy!Appointments prior to 1.5.0 are affected by CVE-2023-38052.
What are the consequences of exploiting CVE-2023-38052?
Exploiting CVE-2023-38052 can lead to significant security breaches, including the exposure and modification of sensitive admin data.