AI Tool Identifies BOLA Vulnerabilities in Easy!Appointments
ID: 9e320b04-bf41-5bd5-a5d2-eb748ea3cebf
STIX ID: report--9e320b04-bf41-5bd5-a5d2-eb748ea3cebf
Feed Name: Palo Alto Networks Unit 42
Unit 42 used an AI-driven BOLA detection tool to audit Easy!Appointments and discovered 15 API-level Broken Object-Level Authorization vulnerabilities (CVE-2023-3285–CVE-2023-3290 and CVE-2023-38047–CVE-2023-38055), many rated critical (seven at CVSS 9.9). The flaws allow low-privileged users to read, modify, delete, or create objects and accounts belonging to higher-privileged users (including creating admin accounts) via API endpoints; maintainers released fixes in Easy!Appointments v1.5.0 and organizations are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
