WordPress 插件 Booktics – Booking Calendar for Appointments and Service Businesses 在所有 1.0.23 及之前版本中均存在未授权数据修改漏洞。该漏洞的成因如下: REST 路由 中的权限回调函数 无条件返回 ,导致该接口无需身份验证即可访问; 函数 在调用方提供的邮箱与现有客户记录匹配时,会覆盖该客户的姓名、电话和 ,且未要求证明邮箱所有权。 这使得未认证的 attackers 可以通过已知客户的邮箱地址,覆盖其联系信息(姓名和电话),
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | Booktics – Appointment Booking Calendar for Service Businesses | 0 ~ 1.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet