Executive brief
EasyAppointments, an open-source appointment scheduling application, contains a security flaw in its customer search feature. An attacker can use this flaw to gain unauthorized access to the underlying database, potentially stealing sensitive customer information or disrupting service. In some server configurations, this could even allow an attacker to take complete control of the web server by running malicious code.
Technical details
A blind SQL injection vulnerability exists in the 'order_by' parameter of the '/customers/search' endpoint in EasyAppointments <= 1.5.1. The issue stems from the application passing unsanitized user input directly into the CodeIgniter Query Builder's order_by method. An unauthenticated remote attacker can exploit this to perform time-based blind SQL queries to enumerate the database schema and exfiltrate data. Furthermore, in environments where the MySQL user has FILE privileges and the 'secure_file_priv' global variable is misconfigured, an attacker can leverage 'INTO OUTFILE' to write a PHP shell to the web directory, resulting in remote code execution (RCE). A fix has been committed to the 'develop' branch (commit 0f0d71c), but a stable release is pending.
Affected products
- Alex Tselegidis EasyAppointments <= 1.5.1
Timeline
- 2026-07-27: disclosed: CVE published to NVD
- 2025-08-27: other: Vulnerability identified and patch committed to develop branch (approximate date based on social media post age)