📦 Easyappointments

by Easyappointments

🔍 What is Easyappointments?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57602

CRITICAL CVSS 9.8 Feb 12, 2025

A privilege escalation vulnerability in EasyAppointments v1.5.0 allows remote attackers to gain elevated privileges through the index.php file. This affects all installations running the vulnerable ve...

CVE-2023-3287

CRITICAL CVSS 9.9 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling software. It allows low-privileged users to create administrator accounts, leading to pr...

CVE-2023-38050

CRITICAL CVSS 9.1 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments webhook endpoints that allows low-privileged authenticated users to access, modify, or delete any user'...

CVE-2023-38052

CRITICAL CVSS 9.9 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments that allows low-privileged users to access, modify, or delete administrator accounts by manipulating ad...

CVE-2023-38054

CRITICAL CVSS 9.9 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments where low-privileged users can access, modify, or delete other users' data by manipulating customer IDs...

CVE-2023-38048

CRITICAL CVSS 9.9 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments that allows low-privileged users to access, modify, or delete privileged provider accounts. Attackers c...

CVE-2023-1269

CRITICAL CVSS 9.8 Mar 8, 2023

CVE-2023-1269 involves hard-coded credentials in the easyappointments scheduling software, allowing attackers to gain unauthorized access to the application. This affects all installations using versi...

CVE-2022-0482

CRITICAL CVSS 9.1 Mar 9, 2022

This vulnerability in Easy Appointments allows unauthorized actors to access private personal information stored in the application. It affects all users of Easy Appointments versions prior to 1.4.3 w...

CVE-2023-3286

HIGH CVSS 7.7 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments system where a low-privileged user can create additional low-privileged user accounts (secretaries)...

CVE-2023-3289

HIGH CVSS 7.7 Jul 9, 2024

This Broken Object Level Authorization (BOLA) vulnerability allows low-privileged users to create services for any user in the system, including administrators. This enables unauthorized data manipula...

CVE-2023-38047

HIGH CVSS 8.5 Jul 9, 2024

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling software. It allows low-privileged users to access, modify, or delete any user's appoint...

CVE-2023-2105

HIGH CVSS 8.8 Apr 15, 2023

This session fixation vulnerability in easyappointments allows attackers to hijack user sessions by fixing session IDs before authentication. It affects all users of easyappointments versions prior to...

CVE-2024-57601

MEDIUM CVSS 6.1 Feb 12, 2025

A cross-site scripting (XSS) vulnerability in EasyAppointments v1.5.0 allows remote attackers to inject malicious scripts via the legal_settings parameter. This affects all users running the vulnerabl...