simplybook CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

simplybook vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to simplybook, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-11887 SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution. [email protected] 9.8 2.13% 2019-05-17 2024-11-21
CVE-2019-11489 Incorrect Access Control in the Administrative Management Interface in SimplyBook.me Enterprise before 2019-04-23 allows Authenticated Low-Priv Users to Elevate Privileges to Full Admin Rights via a crafted HTTP PUT Request, as demonstrated by modified JSON data to a /v2/rest/ URI. [email protected] 8.8 0.52% 2019-04-25 2024-11-21
CVE-2019-11488 Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to READ/WRITE Customer or Administrator data via a persistent HTTP GET Request Hash Link Replay, as demonstrated by a login-link from the browser history. [email protected] 8.1 0.60% 2019-04-25 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence