Lucene search

K
cve[email protected]CVE-2024-32720
HistoryMay 17, 2024 - 10:15 a.m.

CVE-2024-32720

2024-05-1710:15:09
CWE-307
web.nvd.nist.gov
32
vulnerability
restriction
authentication
codepeople
appointment hour booking
nvd

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.

Affected configurations

Vulners
Node
codepeopleappointment_booking_calendarRange1.4.56
VendorProductVersionCPE
codepeopleappointment_booking_calendar*cpe:2.3:a:codepeople:appointment_booking_calendar:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "appointment-hour-booking",
    "product": "Appointment Hour Booking",
    "vendor": "CodePeople",
    "versions": [
      {
        "changes": [
          {
            "at": "1.4.57",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.4.56",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%