WordPress 插件“在线排程与预约系统 – Bookly”(版本 28.1 及更早的所有版本)存在不安全的直接对象引用(IDOR)漏洞。该漏洞由对由用户控制的“conversation_id”参数缺乏有效验证所致。 这一漏洞使得未经身份验证的攻击者能够: 1. 读取任意客户的完整 AI 预约对话记录,从而泄露客户的姓名、电子邮件地址、电话号码以及由 AI 助手回显的预约详情; 2. 向任意受害者的对话中注入任意消息,这些注入的消息随后将与完整的私有历史一并重放至云端 AI 工作进程(Cloud AI work
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ladela | Online Scheduling and Appointment Booking System – Bookly | 0 ~ 28.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet