Executive brief
Easy!Appointments, an open-source appointment scheduling application, contains a security flaw that allows one service provider to view and take control of appointments belonging to others. By accessing a specific search feature, an authenticated user can obtain secret identifiers for appointments they do not own. This allows them to reschedule, modify, or delete those appointments, potentially leading to significant operational disruption and unauthorized access to customer scheduling data.
Technical details
An Excessive Data Exposure (CWE-200) vulnerability exists in the `/customers/search` endpoint of Easy!Appointments version 1.5.2. The endpoint fails to implement proper object-level authorization checks, returning sensitive appointment hashes for all customers in the search results regardless of the requesting user's permissions. An authenticated attacker can extract these hashes and use them with the `/calendar/reschedule/{hash}` endpoint to view, modify, or delete appointments belonging to other providers. This effectively allows for a full appointment takeover. The issue is addressed in version 1.6.0.
Affected products
- alextselegidis Easy!Appointments 1.5.2
Timeline
- 2026-06-15: disclosed
- 2026-07-14: advisory: NVD publication date
- 2026-07-29: advisory: GitHub Advisory reviewed
- 2026-07-29: patched: Release 1.6.0 available