What the vulnerability does
01Description
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Explanation of Vulnerability in Simple Terms
The Salon booking system contains an authentication bypass vulnerability that allows attackers to gain unauthorized access without valid credentials. An attacker can exploit an alternate authentication path to read, modify, or delete sensitive data and disrupt service availability. No user interaction or special privileges are required. All versions up to 10.30.26 are affected.
What an attacker can do
Bypass authentication and gain full access to read, modify, or delete data and disrupt the booking system.
Potential impact on your site
Attackers can access customer data, bookings, and payment information without a valid account or password.
Conditions required to exploit
Network access only; no authentication, special privileges, or user interaction required.
Key dates
External resources
Related vulnerabilities