15 BOLA Blunders Found in Easy!Appointments: Upgrade Now or Brace for Impact!

Palo Alto Networks’ Unit 42 researchers discovered 15 BOLA vulnerabilities in Easy!Appointments using an automated AI tool. The vulnerabilities allowed low-privileged users to manipulate data of higher-privileged users. After notifying the vendor, all issues were patched in version 1.5.0. This highlights the importance of continuous software scrutiny for API vulnerabilities.

Pro Dashboard

Hot Take:

Looks like Easy!Appointments just got a not-so-easy wake-up call! With 15 BOLA vulnerabilities found, it’s clear this calendar app needs a better security appointment. Can someone set a reminder for that?

Key Points:

  • Palo Alto Networks’ Unit 42 developed an AI-based tool to detect BOLA vulnerabilities.
  • 15 BOLA vulnerabilities were found in the popular scheduling app Easy!Appointments.
  • The vulnerabilities allowed low-privileged users to access and manipulate higher-privileged data.
  • All vulnerabilities have been patched in the latest version 1.5.0.
  • Organizations are advised to update to the latest version immediately.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?