// For flags

CVE-2023-24058

 

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.

Booked Scheduler 2.5.5 permite a los usuarios autenticados crear y programar eventos para cualquier otro usuario a través de un valor de ID de usuario modificado en reservation_save.php. NOTA: 2.5.5 es una versión de 2014; la última versión de Booked Scheduler no se ve afectada. Sin embargo, LabArchives Scheduler (versión de funciones del 6 de septiembre de 2022) se ve afectado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-22 CVE Reserved
  • 2023-01-22 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • 2024-08-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Twinkletoessoftware
Search vendor "Twinkletoessoftware"
Booked
Search vendor "Twinkletoessoftware" for product "Booked"
2.5.5
Search vendor "Twinkletoessoftware" for product "Booked" and version "2.5.5"
-
Affected