Executive brief
Easy!Appointments, an open-source appointment scheduling platform, contains a security flaw that allows users with low-level access (such as customers or service providers) to execute unauthorized database commands. By sending specially crafted requests, an attacker could potentially access sensitive information, modify records, or disrupt the scheduling service. This could lead to the exposure of customer data or unauthorized changes to business appointments.
Technical details
A SQL injection vulnerability exists in Easy!Appointments v1.5.1 due to improper neutralization of the 'order_by' parameter in several backend search endpoints. Low-privileged authenticated users (such as Customers and Providers) can exploit this via the /customers/search, /Unavailabilities/search, and /Appointments/search endpoints by submitting a crafted HTTP POST request. The vulnerability manifests as a time-based blind SQL injection (e.g., using SLEEP commands), allowing an attacker to extract data from the underlying MySQL database. Administrative endpoints are also affected but require higher privileges. The issue is resolved in version 1.5.2.
Affected products
- alextselegidis Easy!Appointments 1.5.1
Timeline
- 2025-08-25: disclosed
- 2025-08-25: advisory
- 2025-08-25: patched: Fixed in version 1.5.2