Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects OpenReception's appointment booking software, allowing a tenant administrator to gain full administrative control over the entire platform, including all other tenants' data and configurations. This privilege escalation could expose sensitive appointment details and operational metadata across the service if not addressed. The main concern is confirming relevance and exposure.
- Tenant admin gains full platform control.
- Impacts all customer data and configurations.
- Confirm relevance and exposure to all tenants.
Attack Path
How an attacker could exploit the issue
An attacker with tenant administrator privileges can escalate their access to a platform-wide administrator. This is achieved by sending a specific request that bypasses authorization checks, effectively granting them control over all tenant data and configurations.
- Tenant administrator access required.
- Triggered by a PUT request to update roles.
- Risk: Full platform administrative control.
Live Threat
Current exploitation, exposure, and threat context
A tenant administrator could gain unrestricted administrative control over the entire platform, affecting all customer data and system configurations. This could occur when a tenant administrator uses a specific request to promote themselves to a global administrator, bypassing necessary policy checks.
- Tenant data and platform configuration.
- Admin promotes self via PUT request.
- Full platform administrative control.
Operational Fix
Recommended remediation, mitigation, and detection steps
The critical privilege escalation vulnerability in OpenReception's appointment booking software necessitates immediate attention from platform administrators and application owners. The first practical step is to identify all instances of the affected software, determine their reachability and business criticality, and confirm the accountable owner for each deployment. Remediation planning should then be prioritized based on the identified risk, with a focus on coordinating with the vendor for updates or implementing compensating controls if immediate patching is not feasible.
- Platform or application owners should investigate.
- Verify affected deployments and business impact.
- Coordinate vendor updates or apply controls.