15 BOLA Blunders Found in Easy!Appointments: Upgrade Now or Brace for Impact!
Palo Alto Networks’ Unit 42 researchers discovered 15 BOLA vulnerabilities in Easy!Appointments using an automated AI tool. The vulnerabilities allowed low-privileged users to manipulate data of higher-privileged users. After notifying the vendor, all issues were patched in version 1.5.0. This highlights the importance of continuous software scrutiny for API vulnerabilities.

Hot Take:
Looks like Easy!Appointments just got a not-so-easy wake-up call! With 15 BOLA vulnerabilities found, it’s clear this calendar app needs a better security appointment. Can someone set a reminder for that?
Key Points:
- Palo Alto Networks’ Unit 42 developed an AI-based tool to detect BOLA vulnerabilities.
- 15 BOLA vulnerabilities were found in the popular scheduling app Easy!Appointments.
- The vulnerabilities allowed low-privileged users to access and manipulate higher-privileged data.
- All vulnerabilities have been patched in the latest version 1.5.0.
- Organizations are advised to update to the latest version immediately.
Already a member? Log in here