Vulnerabilities (CVE)

Filtered by vendor Easyappointments Subscribe
Filtered by product Easyappointments
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38047 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 8.5 HIGH
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
CVE-2023-1367 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 3.8 LOW
Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2023-1269 1 Easyappointments 1 Easyappointments 2024-11-21 N/A 9.8 CRITICAL
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
CVE-2022-1397 1 Easyappointments 1 Easyappointments 2024-11-21 9.0 HIGH 8.8 HIGH
API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.
CVE-2022-0482 1 Easyappointments 1 Easyappointments 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.