MEDIUM5.4
GHSA-fc4g-f42p-7rhp
alextselegidis/easyappointments Improper Access Control vulnerability
Details
alextselegidis/easyappointments 1.4.3 and prior allows one provider to view and edit others providers' appointment details. A patch is available at commit 75b24735767868344193fb2cc56e17ee4b9ac4be and anticipated to be part of version 1.5.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/alextselegidis/easyappointments
Introduced in:
0No fixed version published yet for alextselegidis/easyappointments (composer). Pin to a known-safe version or switch to an alternative.