CVE-2023-24058EPSS p53.4%
CVE-2023-24058CVE-2023-24058
twinkletoessoftware / booked
Description
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.85% probability of exploitation · percentile 53.4% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-17 |