Skip to main content

Authorization Bypass Through User-Controlled Key

CVE-2023-38048

Severity High
Score 8.1/10

Summary

A BOLA vulnerability in "GET", "PUT", and "DELETE" methods of "/providers/{providerId}" endpoint, in alextselegidis/easyappointments package versions prior to 1.5.0. This flaw allows a low privileged user to "fetch", "modify", or "delete" a privileged user (provider). This results in unauthorized access and unauthorized data manipulation.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-639 - Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Advisory Timeline

  • Published