Log Injection and Denial of Service Vulnerability in OpenReception Appointment Booking Software
CVE-2026-48083

6.5MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-48083?

OpenReception's appointment booking software allows unauthenticated POST requests to the /api/log endpoint prior to version 1.0.2. This oversight permits log injection attacks, where attackers can insert deceptive log lines that mimic legitimate system events. This behavior can mislead administrators analyzing logs, allowing malicious actors to obscure their activities. The software is also vulnerable to log volume Denial of Service, where excessive logging requests can saturate the logging pipeline, impacting performance and availability. Furthermore, the system accepts large payloads, increasing the risk of abuse. An update to version 1.0.2 addresses these vulnerabilities, enhancing the integrity and security of the log management process.

Affected Version(s)

appointment-booking-software < 1.0.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.