Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34595
HistoryMar 10, 2022 - 6:57 a.m.

Information Disclosure

2022-03-1006:57:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
information disclosure
remote attackers
private information
active appointments
integrity compromise
vulnerable software

EPSS

0.244

Percentile

96.7%

alextselegidis/easyappointments is vulnerable to information disclosure. Remote unauthenticated attackers are able to gain access to private information such as name, email, phone, address, hashed password for all the customers with active appointments in the system. Using index.php/appointments/index/ endpoint attackers are also able to delete appointments and compromise the integrity of the system.