VDB
Sign up
HIGH8.8

GHSA-7f62-4887-cfv5

Privilege escalation in easyappointments

Details

The Easy!Appointments API authorization is checked against the user's existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the "/api/v1/admins/" endpoint and take over the system. A [patch](https://github.com/alextselegidis/easyappointments/commit/63dbb51decfcc1631c398ecd6d30e3a337845526) is available on the `develop` branch of the repository.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/alextselegidis/easyappointments
Introduced in: 0

No fixed version published yet for alextselegidis/easyappointments (composer). Pin to a known-safe version or switch to an alternative.

References