Log Injection and Denial of Service Vulnerability in OpenReception Appointment Booking Software
CVE-2026-48083
What is CVE-2026-48083?
OpenReception's appointment booking software allows unauthenticated POST requests to the /api/log endpoint prior to version 1.0.2. This oversight permits log injection attacks, where attackers can insert deceptive log lines that mimic legitimate system events. This behavior can mislead administrators analyzing logs, allowing malicious actors to obscure their activities. The software is also vulnerable to log volume Denial of Service, where excessive logging requests can saturate the logging pipeline, impacting performance and availability. Furthermore, the system accepts large payloads, increasing the risk of abuse. An update to version 1.0.2 addresses these vulnerabilities, enhancing the integrity and security of the log management process.
Affected Version(s)
appointment-booking-software < 1.0.2
