Lucene search

K
githubGitHub Advisory DatabaseGHSA-347F-RXG8-QGRV
HistoryMar 08, 2023 - 12:30 p.m.

Easy!Appointments uses hard-coded credentials

2023-03-0812:30:16
CWE-798
GitHub Advisory Database
github.com
10
easy!appointments github hard-coded credentials vulnerability software patch available

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

65.4%

Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments 1.4.3 and prior. A patch is available and anticipated to be part of version 1.5.0.

Affected configurations

Vulners
Node
alextselegidiseasyappointmentsRange1.4.3
VendorProductVersionCPE
alextselegidiseasyappointments*cpe:2.3:a:alextselegidis:easyappointments:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

65.4%