CVE-2024-35659: WordPress KiviCare plugin <= 3.6.6 - Insecure Direct Object References (IDOR) vulnerability
Published Jun 8, 2024
·Updated
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.
Affected Software
1 affected component
Iqonic Kivicare Wordpress<=3.6.4
Event History
Jun 8, 2024
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35659?
CVE-2024-35659 is classified as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-35659?
To remediate CVE-2024-35659, update the KiviCare plugin to version 3.6.3 or later.
3
What versions of KiviCare are affected by CVE-2024-35659?
CVE-2024-35659 affects KiviCare versions up to and including 3.6.2.
4
What type of vulnerability is CVE-2024-35659?
CVE-2024-35659 is an authorization bypass vulnerability that allows user-controlled key exploitation.
5
Which product does CVE-2024-35659 impact?
CVE-2024-35659 impacts the KiviCare plugin for WordPress.