TrueBooker – Appointment Booking and Scheduler System(WordPress 插件)在所有 1.2.3 及更早版本中存在授权绕过漏洞。该漏洞源于插件未能正确验证执行特定操作的用户是否已获得相应授权。这使得未认证的 attackers(攻击者)能够修改任意用户账户(包括管理员账户)的电子邮件地址,进而利用该邮箱重置账户密码并获取账户访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themetechmount | TrueBooker – Appointment Booking and Scheduler System | 0 ~ 1.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet