脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
脆弱性説明
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the provider. Any logged-in backend user (admin, provider, or secretary) rebinds a peer provider's Google sync to a Google account they control. The peer's appointments then sync into the attacker's calendar with each customer's name and email attached as attendee data. Version 1.6.0 patches the issue.
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
脆弱性タイプ
通过用户控制密钥绕过授权机制
脆弱性タイトル
Alex Tselegidis Easy!Appointments 授权问题漏洞
脆弱性説明
Alex Tselegidis Easy!Appointments是Alex Tselegidis个人开发者的一个在线预约系统。 Alex Tselegidis Easy!Appointments 1.6.0之前版本存在授权问题漏洞,该漏洞源于对Google OAuth回调中provider_id的授权检查不当,可能导致已登录的后端用户(管理员、服务提供商或秘书)重新绑定同行的Google同步到其控制的账户,从而导致同行的预约数据(包含客户姓名和邮箱)同步到攻击者的日历中。
CVSS情報
N/A
脆弱性タイプ
N/A