
Easy!Appointments v1.5.1의 인증되지 않은 예약 로직 결함으로 인한 서비스 거부
Easy!Appointments v1.5.1의 예약 로직 결함으로 인해 인증되지 않은 공격자가 과도하게 긴 기간의 약속을 생성하여, 향후 모든 예약 가능 시간을 차단함으로써 서비스 거부를 유발할 수 있습니다.
post_data[appointment][end_datetime] 매개변수를 찾습니다.https://github.com/alextselegidis/easyappointments/commit/74633b60f28bdef3cc9f905c0599cef121fee32b