Skip to main content

Authorization Bypass Through User-Controlled Key

CVE-2023-38051

Severity High
Score 8.1/10

Summary

A BOLA vulnerability in "GET", "PUT", "DELETE" methods of "/secretaries/{secretaryId}" endpoint, in alextselegidis/easyappointments package versions prior to 1.5.0. This flaw allows a low-privileged user to fetch, modify, or delete a low-privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-639 - Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Advisory Timeline

  • Published