PT-2022-13450 · WordPress · Amelia

Huli

·

Published

2022-04-04

·

Updated

2022-06-03

·

CVE-2022-0825

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Amelia WordPress plugin versions prior to 1.0.49
Description The issue concerns a lack of proper authorization when managing appointments. This allows any customer to update the booking status of others and retrieve sensitive information about bookings, including the full name and phone number of the person who made the booking.
Recommendations For versions prior to 1.0.49, update to version 1.0.49 or later to resolve the issue. As a temporary workaround, consider restricting access to appointment management features to minimize the risk of unauthorized updates or data retrieval.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0825

Affected Products

Amelia