CVE-2023-24058: Twinkletoessoftware Booked
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.
Affected products
- Twinkletoessoftware Booked: version 2.5.5 only
Published 2023-01-22. Last modified 2026-06-17.