Cyber Posture

CVE-2024-57602

CriticalPublic PoC

Published: 12 February 2025

Published
12 February 2025
Modified
18 March 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0110 78.1th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

Security Summary

CVE-2024-57602 is a privilege escalation vulnerability in Alex Tselegidis EasyAppointments version 1.5.0. The flaw exists in the index.php file, allowing a remote attacker to improperly elevate their access level. It has been assigned a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-269 (Improper Privilege Management), though additional CWE details are unavailable from NVD.

The vulnerability can be exploited by any remote attacker with network access, requiring no authentication privileges, low complexity, and no user interaction. Successful exploitation enables the attacker to gain elevated privileges, resulting in high impacts across confidentiality, integrity, and availability, potentially allowing full compromise of the affected EasyAppointments instance.

Mitigation details are available in the advisory published at https://hkohi.ca/vulnerability/12, which was referenced alongside the CVE disclosure on 2025-02-12. Security practitioners should consult this source for patching instructions or workarounds specific to EasyAppointments v1.5.0.

Details

CWE(s)
NVD-CWE-noinfoCWE-269

Affected Products

easyappointments
easyappointments
1.5.0

References