CVE-2024-57602: Critical severity easy!appointments vulnerability
Published Feb 12, 2025
·Updated
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
Affected Software
3 affected components
Alex Tselegidis EasyAppointments
EasyAppointments EasyAppointments=1.5.0
composer/alextselegidis/easyappointments<=1.5.0
Event History
Feb 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 13, 2025
Advisory Published
via GitHub·12:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-57602?
CVE-2024-57602 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-57602?
To mitigate CVE-2024-57602, update EasyAppointments to the latest version that addresses the privilege escalation issue.
3
What impact does CVE-2024-57602 have on my system?
CVE-2024-57602 allows remote attackers to escalate privileges, potentially compromising sensitive data and system integrity.
4
Who is affected by CVE-2024-57602?
CVE-2024-57602 affects users of Alex Tselegidis EasyAppointments version 1.5.0.
5
Can CVE-2024-57602 be exploited remotely?
Yes, CVE-2024-57602 can be exploited remotely through the index.php file.