PT-2023-19380 · Unknown · Booked Scheduler+1
Published
2023-01-22
·
Updated
2023-01-31
·
CVE-2023-24058
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Booked Scheduler version 2.5.5
LabArchives Scheduler (affected versions not specified)
Description
The issue allows authenticated users to create and schedule events for any other user by modifying the
userId value in the reservation save.php endpoint. This affects older versions of the software, with Booked Scheduler 2.5.5, a version from 2014, being specifically mentioned as vulnerable. The latest version of Booked Scheduler is not affected. However, LabArchives Scheduler is also impacted, as noted in its September 6, 2022, Feature Release.Recommendations
For Booked Scheduler version 2.5.5, consider upgrading to a newer version, as 2.5.5 is outdated and the latest version is not affected.
For LabArchives Scheduler, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
reservation save.php endpoint to minimize the risk of exploitation. Avoid using the modified userId value in this endpoint until the issue is resolved.Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booked Scheduler
Labarchives Scheduler