Horizon Alert
Summary of the vulnerability and why it matters
OpenReception's appointment booking software has a critical vulnerability that allows unauthenticated attackers to create new administrative accounts and gain full control of the platform. This issue affects instances prior to version 1.0.1 and could allow unauthorized users to access and manipulate appointment data. The main concern is confirming relevance and exposure to this type of platform.
- Attackers can seize administrative control of booking software.
- It allows unauthorized access to sensitive booking information.
- Confirm if this booking software is in use.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker on the network can gain full administrative control of an OpenReception instance by sending a specially crafted POST request to the `/setup/create-admin-account` endpoint. This bypasses existing security checks after the initial setup, allowing the attacker to create new administrator accounts without proper verification. The vulnerability can lead to complete compromise of the platform.
- Attacker can access the vulnerable endpoint remotely.
- Sending an unauthenticated POST request triggers the vulnerability.
- Full administrative control of the platform is the risk.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, unauthenticated network attackers could gain full administrative control over the OpenReception appointment booking platform by exploiting a vulnerability in the account creation process. This could allow them to create additional administrative accounts without proper verification, potentially compromising the entire platform.
- Platform administrative control.
- Unauthenticated POST requests to `/setup/create-admin-account`.
- Full platform-level administrative control.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application and infrastructure teams are likely responsible for securing the OpenReception appointment booking software. The initial practical step is to identify all instances, confirm their exposure and criticality, and determine the accountable owner. Planning remediation should then be based on the assessed risk to the business.
- Identify affected instances and owners.
- Verify network reachability and business criticality.
- Plan remediation based on risk assessment.