CVE-2022-0482
critical · 9.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
9.1
CVSS
43.7%
EPSS (exploit prob.)
99th
EPSS percentile
2022-03-09
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-359CWE-863
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| easyappointments | easyappointments | < 1.4.3 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.html
- https://github.com/alextselegidis/easyappointments/commit/44af526a6fc5e898bc1e0132b2af9eb3a9b2c466
- https://huntr.dev/bounties/2fe771ef-b615-45ef-9b4d-625978042e26
- https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/
- http://packetstormsecurity.com/files/166701/Easy-Appointments-Information-Disclosure.html
- https://github.com/alextselegidis/easyappointments/commit/44af526a6fc5e898bc1e0132b2af9eb3a9b2c466
- https://huntr.dev/bounties/2fe771ef-b615-45ef-9b4d-625978042e26
- https://opencirt.com/hacking/securing-easy-appointments-cve-2022-0482/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-0482