Privilege escalation in easyappointments

The Easy!Appointments API authorization is checked against the user’s existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the “/api/v1/admins/” endpoint and take over the system. A [patch]( is available on the `develop` branch of the repository.

Back to Main

Subscribe for the latest news: