CVE-2023-24058
Published on: Not Yet Published
Last Modified on: 01/23/2023 03:08:00 PM UTC
The following vulnerability was found:
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.
- CVE-2023-24058 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
2022 Feature Releases - LabArchives | web.archive.org text/html Inactive LinkNot Archived |
![]() |
app/ReservationSavePage.php at 0a6cb1a9eb84835553c8caf93db2791f8655140f · LibreBooking/app · GitHub | github.com text/html |
![]() |
Tags · LibreBooking/app · GitHub | github.com text/html |
![]() |
Booked - LIMSWiki | www.limswiki.org text/html |
![]() |
Booked Scheduler v2.5.5 Vulnerability - theB10G | s1n1st3r.gitbook.io application/octet-stream |
![]() |
Big Changes for Booked Scheduler – Booked | www.bookedscheduler.com text/html |
![]() |
app/reservation_save.php at 0a6cb1a9eb84835553c8caf93db2791f8655140f · LibreBooking/app · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
There are no known software configurations (CPEs) currently associated with this CVE
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-24058 : Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user… twitter.com/i/web/status/1… | 2023-01-22 06:03:51 |
![]() |
CVE-2023-24058 | Booked Scheduler 2.5.5 reservation_save.php userId access control A vulnerability classified as cr… twitter.com/i/web/status/1… | 2023-01-22 17:50:29 |