AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11488

HIGH · CVSS 8.1 EPSS 1.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-04-25 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-11488
Severity
HIGH
CVSS
8.1
EPSS
1.54%

Original NVD Description

Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allows Unauthorized Attackers to READ/WRITE Customer or Administrator data via a persistent HTTP GET Request Hash Link Replay, as demonstrated by a login-link from the browser history.