« Volver al listado

CVE-2023-38053

Estado: ModificadaAlta (8.1)—

A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-38053",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-38053",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-09T13:50:18.307548Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@paloaltonetworks.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@paloaltonetworks.com",
      "affectedData": [
        {
          "product": "easyappointments",
          "versions": [
            {
              "status": "affected",
              "version": "*",
              "lessThan": "1.5.0",
              "versionType": "git"
            }
          ],
          "packageName": "alextselegidis/easyappointments",
          "collectionURL": "https://github.com/alextselegidis/easyappointments",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:*:*:*"
          ],
          "vendor": "easyappointments",
          "product": "easyappointments",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.5.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-07-09T11:15:11.617",
  "references": [
    {
      "url": "https://github.com/alextselegidis/easyappointments",
      "tags": [
        "Product"
      ],
      "source": "psirt@paloaltonetworks.com"
    },
    {
      "url": "https://github.com/alextselegidis/easyappointments",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@paloaltonetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation."
    },
    {
      "lang": "es",
      "value": " Una vulnerabilidad BOLA en GET, PUT, DELETE /settings/{settingName} permite a un usuario con pocos privilegios recuperar, modificar o eliminar la configuración de cualquier usuario (incluido el administrador). Esto da como resultado un acceso no autorizado y una manipulación de datos no autorizada."
    }
  ],
  "lastModified": "2026-06-17T06:09:19.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "063BC3E9-AA71-49D6-9CEE-F2E7E7B9D687",
              "versionEndExcluding": "1.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@paloaltonetworks.com"
}