CVE-2023-49282
The Amelia booking plugin versions before 1.2.37 contain a vulnerable version of the Microsoft Graph PHP SDK that includes test code exposing the phpInfo() function through a publicly accessible file. An attacker who can access the vendor directory would be able to execute phpInfo() and retrieve sensitive system information including configuration details, loaded modules, and environment variables. This exposure could enable attackers to obtain credentials or other secrets that facilitate further compromise of the application and its infrastructure.
Based on public CVE data (MITRE/NVD).