vendor:
EasyAppointments
by:
noraj (Alexandre ZANNI)
9.1
CVSS
CRITICAL
Exposure of Private Personal Information to an Unauthorized Actor
863
CWE
Product Name: EasyAppointments
Affected Version From: 1.3.2002
Affected Version To: 1.4.2002
Patch Exists: YES
Related CWE: CVE-2022-0482
CPE: a:alextselegidis:easyappointments:1.4.2
Tags: cve,cve2022,easyappointments,huntr
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Nuclei References:
https://huntr.dev/bounties/2fe771ef-b615-45ef-9b4d-625978042e26/, https://github.com/alextselegidis/easyappointments, https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/, https://nvd.nist.gov/vuln/detail/CVE-2022-0482, https://github.com/alextselegidis/easyappointments/commit/44af526a6fc5e898bc1e0132b2af9eb3a9b2c466
Nuclei Metadata: {'max-request': 2, 'framework': 'wordpress', 'vendor': 'easyappointments', 'product': 'easyappointments'}
Platforms Tested: Easy!Appointments Version 1.3.2
2022
Easy Appointments 1.4.2 – Information Disclosure
Easy!Appointments < 1.4.3 is vulnerable to an unauthenticated PII (events) disclosure. An attacker can send a specially crafted request to the backend/ajax/get_available_hours endpoint to retrieve events between a given start and end date. The response contains the customer's name, email, phone number and notes.
Mitigation:
Upgrade to Easy!Appointments version 1.4.3 or later.