Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
97Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.1epss 44%
from disclosure to weapon35 days
Published on NVDMar 9
1st PoC+35d
VulnCheck+618d
exploitation probability
44%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
alextselegidis · alextselegidis/easyappointmentspublic PoCs found — 5
exploitdbwww.exploit-db.com/exploits/50871unverifiedgithubgithub.com/Acceis/exploit-CVE-2022-0482★ 3githubgithub.com/mija-pilkaite/CVE-2022-0482_exploit★ 1cve_referencepacketstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.htmlunverifiedvulncheckvulncheck.com/xdb/260c0275bfbbunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.htmlhttps://github.com/alextselegidis/easyappointments/commit/44af526a6fc5e898bc1e0132b2af9eb3a9b2c466https://huntr.dev/bounties/2fe771ef-b615-45ef-9b4d-625978042e26https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/