What the vulnerability does
01Description
Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.
Explanation of Vulnerability in Simple Terms
Easy!Appointments versions up to 1.3.3 lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition affecting the entire application. The vulnerability requires network access and low-level user credentials but no user interaction. Impact extends beyond the vulnerable component due to scope change.
What an attacker can do
Authenticated user can make the application unavailable to other users.
Potential impact on your site
Legitimate users may be unable to access the appointment booking system during an attack.
Conditions required to exploit
Attacker must have a low-privilege user account on the Easy!Appointments installation.
Key dates
External resources
Related vulnerabilities