PT-2023-31801 · Unknown · Sandbox Accounts For Events
Mahmoud0X00
·
Published
2023-12-22
·
Updated
2024-01-04
·
CVE-2023-51386
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sandbox Accounts for Events versions prior to 1.10.0
Description
The issue allows authenticated users to potentially read data from the events table by sending request payloads to the "events API", collecting information on planned events, timeframes, budgets, and owner email addresses. This data access may allow users to get insights into upcoming events and join events which they have not been invited to.
Recommendations
For versions prior to 1.10.0, update to version 1.10.0 to resolve the issue. As a temporary workaround, consider restricting access to the "events API" to minimize the risk of exploitation. Avoid using the events API to collect sensitive information until the issue is resolved.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sandbox Accounts For Events