PT-2024-30099 · Unknown · Slabiak Appointment Scheduler

Abbisqq

·

Published

2024-09-05

·

Updated

2025-01-31

·

CVE-2024-42671

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions slabiak Appointment Scheduler version 1.0.5
Description A Host Header Poisoning Open Redirect issue allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities.
Recommendations For slabiak Appointment Scheduler version 1.0.5, consider disabling the open redirect functionality until a patch is available. Restrict access to the scheduler to minimize the risk of exploitation. Avoid using the scheduler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-42671

Affected Products

Slabiak Appointment Scheduler