GHSA-7f62-4887-cfv5
Dashboard / Vulnerabilities / GHSA-7f62-4887-cfv5
Summary: Privilege escalation in easyappointments
Details: The Easy!Appointments API authorization is checked against the user's existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the "/api/v1/admins/" endpoint and take over the system. A [patch](https://github.com/alextselegidis/easyappointments/commit/63dbb51decfcc1631c398ecd6d30e3a337845526) is available on the `develop` branch of the repository.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-1397, https://github.com/alextselegidis/easyappointments/commit/63dbb51decfcc1631c398ecd6d30e3a337845526, https://github.com/alextselegidis/easyappointments, https://huntr.dev/bounties/5f69e094-ab8c-47a3-b01d-8c12a3b14c61
Affected packages
Package
Name: alextselegidis/easyappointments
Purl: pkg:composer/alextselegidis/easyappointments
Affected ranges
Type: ECOSYSTEM
Events:
