WordPress 的 Simply Schedule Appointments 插件在包括 1.6.12.31 在内的所有版本中均存在不安全的直接对象引用(IDOR)漏洞。该漏洞源于对由用户控制的键值缺少验证,具体通过 参数触发。 这使得拥有订阅者(subscriber)级别或更高权限的已认证攻击者能够泄露同一预约组中每位共同预订者的私有 (以 形式暴露)及其个人身份信息(PII,包括姓名和电子邮件地址)。随后,攻击者可利用每个泄露的令牌,通过相同的 REST 控制器读取、覆盖任意预约元数据(appointmen
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| croixhaug | Simply Schedule Appointments | 0 ~ 1.6.12.31 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet