4.3

CVE-2023-24058

Exploit
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TwinkletoessoftwareBooked Version2.5.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.534
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://github.com/LibreBooking/app/blob/0a6cb1a9eb84835553c8caf93db2791f8655140f/Pages/Ajax/ReservationSavePage.php#L234-L237
Third Party Advisory
Exploit
https://github.com/LibreBooking/app/blob/0a6cb1a9eb84835553c8caf93db2791f8655140f/Web/ajax/reservation_save.php
Third Party Advisory
Exploit
https://github.com/LibreBooking/app/tags?after=2.7.1
Third Party Advisory
https://s1n1st3r.gitbook.io/theb10g/booked-scheduler-v2.5.5-vulnerability
Third Party Advisory
Exploit
https://www.bookedscheduler.com/the-future-of-booked/
Vendor Advisory
https://www.labarchives.com/labarchives-knowledge-base/2022-feature-releases-2/
Vendor Advisory
Release Notes
https://www.limswiki.org/index.php/Booked
Third Party Advisory