What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon booking system: from n/a through <= 10.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon booking system: from n/a through <= 10.9.
Explanation of Vulnerability in Simple Terms
The Salon booking system contains an authorization flaw that allows authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter information through the application's interface. The vulnerability affects versions up to 10.9. No patch version has been publicly identified.
What an attacker can do
Modify data or settings in the booking system that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized changes to booking data, customer information, or system settings by low-privilege users.
Conditions required to exploit
Attacker must have a valid low-privilege account and network access to the application.
Key dates
External resources
Related vulnerabilities