PT-2023-30981 · Unknown · Appointment Scheduler

Published

2023-12-07

·

Updated

2023-12-09

·

CVE-2023-48838

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Appointment Scheduler version 3.0
Description The issue concerns Multiple HTML Injection problems. These issues can be exploited via the SMS API Key or Default Country Code.
Recommendations For Appointment Scheduler version 3.0, consider disabling the SMS API Key or restricting its use until a patch is available. Additionally, review and secure the Default Country Code configuration to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-48838

Affected Products

Appointment Scheduler