Authorization Bypass Through User-Controlled Key
CVE-2023-38048
Summary
A BOLA vulnerability in "GET", "PUT", and "DELETE" methods of "/providers/{providerId}" endpoint, in alextselegidis/easyappointments package versions prior to 1.5.0. This flaw allows a low privileged user to "fetch", "modify", or "delete" a privileged user (provider). This results in unauthorized access and unauthorized data manipulation.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-639 - Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Advisory Timeline
- Published