Lucene search

K
osvGoogleOSV:GHSA-7F62-4887-CFV5
HistoryMay 11, 2022 - 12:01 a.m.

Privilege escalation in easyappointments

2022-05-1100:01:38
Google
osv.dev
19
easy!appointments
api authorization
low privileged user
create admin
system takeover
patch available

EPSS

0.001

Percentile

37.5%

The Easy!Appointments API authorization is checked against the user’s existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the “/api/v1/admins/” endpoint and take over the system. A patch is available on the develop branch of the repository.

EPSS

0.001

Percentile

37.5%

Related for OSV:GHSA-7F62-4887-CFV5