Vulnerabilities in open-reception
17 resultsVexday analysis
Open-reception possui 16 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 4 delas classificadas como críticas; nenhuma está sob exploração ativa no momento. A fraqueza dominante é CWE-862 (autorização inadequada), indicando falhas sistemáticas no controle de acesso que demandam revisão urgente da política de permissões.
CVE-2026-54460CRITICALOpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeoverEPSS 0.6%CVE-2026-48085CRITICALOpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrapEPSS 0.6%CVE-2026-48087CRITICALOpenReception: WebAuthn passkey injection allows account takeoverEPSS 0.5%CVE-2026-48071MEDIUMOpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockoutEPSS 0.4%CVE-2026-48082LOWOpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplificationEPSS 0.4%CVE-2026-48075MEDIUMOpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injectionsEPSS 0.4%CVE-2026-48079HIGHOpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiryEPSS 0.4%CVE-2026-48077MEDIUMOpenReception: GET appointment by ID returns full appointment record without authorizationEPSS 0.4%CVE-2026-48084HIGHOpenReception doesn't rate limit passphrase login attemptsEPSS 0.4%CVE-2026-48083MEDIUMOpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limitsEPSS 0.3%CVE-2026-48086CRITICALOpenReception: Tenant admin self-promotes to GLOBAL_ADMINEPSS 0.3%CVE-2026-48088CRITICALOpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directoryEPSS 0.3%CVE-2026-48074LOWOpenReception: Staff deletion removes pending invites cross-tenant by email matchEPSS 0.3%CVE-2026-48076MEDIUMOpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channelsEPSS 0.3%CVE-2026-48080HIGHOpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deploymentEPSS 0.3%CVE-2026-48078MEDIUMOpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callersEPSS 0.3%CVE-2026-48081HIGHOpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footerEPSS 0.1%