CVE-2019-11489
Incorrect Access Control in the Administrative Management Interface in SimplyBook.me Enterprise before 2019-04-23 allows Authenticated Low-Priv Users to Elevate Privileges to Full Admin Rights via a crafted HTTP PUT Request, as demonstrated by modified…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Incorrect Access Control in the Administrative Management Interface in SimplyBook.me Enterprise before 2019-04-23 allows Authenticated Low-Priv Users to Elevate Privileges to Full Admin Rights via a crafted HTTP PUT Request, as demonstrated by modified JSON data to a /v2/rest/ URI.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- simplybook/simplybook
- Source
- cve@mitre.org
References
- https://blog.cybrgrade.com/CVE-2019-11489-SimplyBook.me-privesc/Exploit, Third Party Advisory
- https://cybrgrade.com/files/Report_SimplyBookIt_Privesc_by_CybrGradeUKLtd.pdfExploit, Third Party Advisory
- https://blog.cybrgrade.com/CVE-2019-11489-SimplyBook.me-privesc/Exploit, Third Party Advisory
- https://cybrgrade.com/files/Report_SimplyBookIt_Privesc_by_CybrGradeUKLtd.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.