Vulnerabilities > Easyappointments > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-09 | CVE-2023-3288 | Authorization Bypass Through User-Controlled Key vulnerability in Easyappointments A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. | 8.8 |
2023-04-15 | CVE-2023-2105 | Unspecified vulnerability in Easyappointments Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | 8.8 |
2022-05-10 | CVE-2022-1397 | Improper Privilege Management vulnerability in Easyappointments API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | 8.8 |
2020-03-16 | CVE-2018-13063 | Missing Authorization vulnerability in Easyappointments Easy!Appointments Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. | 7.5 |