WordPress 预约预订与保留插件 LatePoint 在 5.6.9 及之前版本中存在不安全直接对象引用(IDOR)漏洞。该漏洞源于 函数在将 POST 请求中的客户数据合并到现有 LatePoint 客户记录时,仅以 (用户是否已登录)作为唯一访问控制机制,而未实施任何所有权验证。因此,具有订阅者(Subscriber)级别或更高权限的已认证攻击者可以修改任意 LatePoint 客户个人信息(包括名、姓、电子邮件地址、电话号码和备注)。此外,当 配置设置为 "phone" 时,攻击者还能够覆盖受害者的电子
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | 0 ~ 5.6.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet