HIGH8.8
GHSA-7f62-4887-cfv5
Privilege escalation in easyappointments
Details
The Easy!Appointments API authorization is checked against the user's existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the "/api/v1/admins/" endpoint and take over the system. A [patch](https://github.com/alextselegidis/easyappointments/commit/63dbb51decfcc1631c398ecd6d30e3a337845526) is available on the `develop` branch of the repository.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/alextselegidis/easyappointments
Introduced in:
0No fixed version published yet for alextselegidis/easyappointments (composer). Pin to a known-safe version or switch to an alternative.