CVE-2024-35659

Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*

History

01 Apr 2026, 16:17

Type Values Removed Values Added
CWE CWE-639 CWE-862
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 8.8
Summary (en) Authorization Bypass Through User-Controlled Key vulnerability in KiviCare.This issue affects KiviCare: from n/a through 3.6.2. (en) Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.
References
  • () https://patchstack.com/database/Wordpress/Plugin/kivicare-clinic-management-system/vulnerability/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve -

26 Nov 2024, 16:33

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*
First Time Iqonic
Iqonic kivicare
References () https://patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*
First Time Iqonic
Iqonic kivicare

21 Nov 2024, 09:20

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en KiviCare. Este problema afecta a KiviCare: desde n/a hasta 3.6.2.
References () https://patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/kivicare-clinic-management-system/wordpress-kivicare-plugin-3-6-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve -

08 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-08 16:15

Updated : 2026-04-01 16:17


NVD link : CVE-2024-35659

Mitre link : CVE-2024-35659

CVE.ORG link : CVE-2024-35659


JSON object : View

Products Affected

iqonic

  • kivicare
CWE
CWE-862

Missing Authorization