Where
-Infinity
0

OpenReception appointment booking softwareOpenReception: WebAuthn passkey injection allows account takeover

Risk 86
Severity
9.8
First published (updated )

OpenReception appointment booking softwareOpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits

Risk 40
Severity
6.5
First published (updated )

OpenReception appointment booking softwareOpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry

Risk 56
Severity
7.4
First published (updated )

OpenReception appointment booking softwareOpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers

Risk 27
Severity
5.3
First published (updated )

OpenReception appointment booking softwareOpenReception: GET appointment by ID returns full appointment record without authorization

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenReception appointment booking softwareOpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels

Risk 40
Severity
6.5
First published (updated )

OpenReception appointment booking softwareOpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections

Risk 45
Severity
6.5
First published (updated )

OpenReception appointment booking softwareOpenReception: Staff deletion removes pending invites cross-tenant by email match

Risk 16
Severity
2.7
First published (updated )

OpenReception appointment booking softwareOpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockout

Risk 30
Severity
5.8
First published (updated )

OpenReception appointment booking softwareOpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment

Risk 65
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203