Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
97Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 9.1epss 39%
de la publicación al arma35 días
Publicada en NVD9 mar
1ª PoC+35d
VulnCheck+618d
probabilidad de explotación
39%top 2% de las CVE
explotación observada
síVulnCheck
5 exploit(s) público(s)
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
alextselegidis · alextselegidis/easyappointmentsPoCs públicas encontradas — 5
exploitdbwww.exploit-db.com/exploits/50871no verificadogithubgithub.com/Acceis/exploit-CVE-2022-0482★ 3githubgithub.com/mija-pilkaite/CVE-2022-0482_exploit★ 1cve_referencepacketstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.htmlno verificadovulncheckvulncheck.com/xdb/260c0275bfbbno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.htmlhttps://github.com/alextselegidis/easyappointments/commit/44af526a6fc5e898bc1e0132b2af9eb3a9b2c466https://huntr.dev/bounties/2fe771ef-b615-45ef-9b4d-625978042e26https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/