CVE-2024-57601: Code Injection
Published Feb 12, 2025
·Updated
Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legalsettings parameter.
Affected Software
3 affected components
Alex Tselegidis EasyAppointments
composer/alextselegidis/easyappointments<=1.5.0
EasyAppointments EasyAppointments=1.5.0
Event History
Feb 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
Affected Software
Feb 13, 2025
Advisory Published
via GitHub·12:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-57601?
CVE-2024-57601 is classified as a medium severity vulnerability due to its potential for remote code execution via cross-site scripting.
2
How do I fix CVE-2024-57601?
To fix CVE-2024-57601, it is recommended to update EasyAppointments to at least version 1.5.1 where the vulnerability is addressed.
3
What is the impact of CVE-2024-57601?
The impact of CVE-2024-57601 allows a remote attacker to execute arbitrary code on the affected system through crafted input in the legal_settings parameter.
4
Which versions of EasyAppointments are affected by CVE-2024-57601?
CVE-2024-57601 affects EasyAppointments versions up to and including 1.5.0.
5
Who is the vendor for CVE-2024-57601?
The vendor for CVE-2024-57601 is Alex Tselegidis, the creator of EasyAppointments.