PT-2024-30099 · Unknown · Slabiak Appointment Scheduler
Abbisqq
·
Published
2024-09-05
·
Updated
2025-01-31
·
CVE-2024-42671
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
slabiak Appointment Scheduler version 1.0.5
Description
A Host Header Poisoning Open Redirect issue allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities.
Recommendations
For slabiak Appointment Scheduler version 1.0.5, consider disabling the open redirect functionality until a patch is available. Restrict access to the scheduler to minimize the risk of exploitation. Avoid using the scheduler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Open Redirect
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Slabiak Appointment Scheduler