PT-2023-3709 · Unknown · Easyappointments

Publicado

2023-07-17

·

Atualizado

2023-08-02

·

CVE-2023-3700

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions easyappointments versions prior to 1.5.0
Description The issue is related to improper access control in the easyappointments application, which can allow a remote attacker to gain unauthorized access to restricted functions. This is due to a lack of control over user access.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive functions until the update is applied.

Exploit

Correção

IDOR

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03997
CVE-2023-3700
GHSA-8C6Q-26W6-QWHG

Produtos afetados

Easyappointments