User Impersonation Vulnerability in Booked Scheduler 2.5.5 and LabArchives Scheduler (Sep 6, 2022 Feature Release)

User Impersonation Vulnerability in Booked Scheduler 2.5.5 and LabArchives Scheduler (Sep 6, 2022 Feature Release)

CVE-2023-24058 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.

Learn more about our User Device Pen Test.