logo

AI Tool Identifies BOLA Vulnerabilities in Easy!Appointments

ID: 9e320b04-bf41-5bd5-a5d2-eb748ea3cebf

STIX ID: report--9e320b04-bf41-5bd5-a5d2-eb748ea3cebf

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-07-25

Date Updated: 2026-04-28

Author: Ravid Mazon and Jay Chen

...
...

Unit 42 used an AI-driven BOLA detection tool to audit Easy!Appointments and discovered 15 API-level Broken Object-Level Authorization vulnerabilities (CVE-2023-3285–CVE-2023-3290 and CVE-2023-38047–CVE-2023-38055), many rated critical (seven at CVSS 9.9). The flaws allow low-privileged users to read, modify, delete, or create objects and accounts belonging to higher-privileged users (including creating admin accounts) via API endpoints; maintainers released fixes in Easy!Appointments v1.5.0 and organizations are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.