CVE-2019-11488

HIGH

SimplyBook.me Enterprise <2019-04-23 - Info Disclosure

Title source: llm
STIX 2.1

Description

Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to READ/WRITE Customer or Administrator data via a persistent HTTP GET Request Hash Link Replay, as demonstrated by a login-link from the browser history.

References (2)

Core 2
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://cybrgrade.com/files/Report_SimplyBookIt_MD5_Hash_Replay_by_CybrGradeUKLtd.pdf

Scores

CVSS v3 8.1
EPSS 0.0154
EPSS Percentile 71.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
simplybook/simplybook < 2019-04-23
Published Apr 25, 2019
Tracked Since Feb 18, 2026