PT-2026-58044 · Unknown · Easyappointments

CVE-2026-52837

·

Published

2026-07-14

·

Updated

2026-07-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Easy!Appointments versions prior to 1.6.0
Description The booking reschedule view at the endpoint /index.php/booking/reschedule/{appointment hash} (handled by the Booking::index() function) embeds the complete customer record as inline JavaScript within the customer data variable. This occurs without authentication or field whitelisting. An individual with the 12-character appointment hash variable—found in reschedule emails, confirmation page URLs, and operator-side calendar links—can access all columns of the customer's row in the ea users table.
Recommendations Update to version 1.6.0.

Exploit

Fix

IDOR

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52837
GHSA-XGR6-PQJV-3PF8

Affected Products

Easyappointments