CVE-2023-3288

Published
View on NVD ↗
CVSS v3
8.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.

:date: Easy!Appointments - Self Hosted Appointment Scheduler
GitHubGitHub
4.2K