Impact
Easy!Appointments versions through 1.6.0 contain a flaw in the Booking::register() handler that allows an attacker who is not authenticated to change the details of any existing appointment. By supplying only an appointment identifier and omitting the associated hash, the endpoint accepts the update and rewrites the appointment record. This permits attackers to rebind appointments to customers of their choosing, modify scheduled times, and gain the ability to cancel or reschedule appointments using the newly issued management hashes. The weakness is a classic authorization bypass and can be used to impersonate legitimate users or disrupt service scheduling.
Affected Systems
The vulnerability affects the Easy!Appointments software supplied by the Alec Tselegidis organization, specifically all releases up to and including version 1.6.0. The issue resides in the core booking controller and is present whenever the /booking/register endpoint is exposed, regardless of deployment environment. Endpoints that rely on appointment identifiers without additional cryptographic verification are subject to attack.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity, and it is not listed in CISA's KEV catalog. No EPSS score is available, but the lack of protection allows straightforward enumeration of appointment identifiers, especially when the attacker can set a self‐asserting manage_mode flag. The structure of the API enables the attacker to meet the conditions for exploitation without needing privileged credentials, making the risk significant for installations where the booking endpoint is publicly reachable.
OpenCVE Enrichment