Beveiligingsadvies

CVE-2023-3285

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-07-09 09:37:24
Laatst bijgewerkt 2024-08-02 06:48:08
Toegewezen door palo_alto
CVSS-score 7.7
Status PUBLISHED

Beschrijving

A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.