PT-2026-58044 · Unknown · Easyappointments
CVE-2026-52837
·
Published
2026-07-14
·
Updated
2026-07-29
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Easy!Appointments versions prior to 1.6.0
Description
The booking reschedule view at the endpoint
/index.php/booking/reschedule/{appointment hash} (handled by the Booking::index() function) embeds the complete customer record as inline JavaScript within the customer data variable. This occurs without authentication or field whitelisting. An individual with the 12-character appointment hash variable—found in reschedule emails, confirmation page URLs, and operator-side calendar links—can access all columns of the customer's row in the ea users table.Recommendations
Update to version 1.6.0.
Exploit
Fix
IDOR
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easyappointments