What the vulnerability does
01Description
Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211.
Explanation of Vulnerability in Simple Terms
02Summary
ReDi Restaurant Reservation versions up to 23.0211 lack proper authorization checks, allowing unauthenticated attackers to read, modify, or delete reservation data over the network. No special conditions or user interaction are required. Site administrators should update to a version newer than 23.0211 immediately.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete restaurant reservations without logging in.
Potential impact on your site
04Site Impact
Attackers can access, alter, or destroy reservation records, disrupting business operations and customer trust.
Conditions required to exploit
05Prerequisites
Network access to the ReDi application; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 28, 2026
Record updated