WordPress 的 Simply Schedule Appointments 插件在包括 1.6.12.32 在内的所有版本中,存在通过 参数导致的敏感信息暴露漏洞。该漏洞允许未经身份验证的攻击者提取存储在预约记录中的客户个人身份信息(PII),包括姓名、电子邮件地址、电话号码以及自定义表单字段数据,同时还可获取每个预约对应的 值。泄露的 值还使得未经身份验证的攻击者能够通过 端点删除任意预约,因为该端点仅将 token 作为唯一的授权凭证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| croixhaug | Simply Schedule Appointments | 0 ~ 1.6.12.32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet