Impact
Easy!Appointments versions below 1.6.0 allow a logged‑in backend user—admin, provider, or secretary—to rebind a peer provider’s Google sync to their own Google account because the OAuth callback does not verify provider ownership. The rebind causes that provider’s appointments, along with customer names and emails, to be synced to the attacker’s calendar, exposing sensitive customer information. This is an authorization bypass that results in unauthorized data disclosure.
Affected Systems
The vulnerability affects all releases of Easy!Appointments from every vendor version prior to 1.6.0. The specific product impacted is alextselegidis:easyappointments, with the affected range being all versions less than 1.6.0.
Risk and Exploitability
The CVSS score of 3.1 marks it as low severity, and the EPSS < 1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with backend privileges to perform a simple rebind action; no external attack vector is needed. Because the attacker can gain visibility of all appointments for a provider, the impact on confidentiality is significant, though the overall risk remains moderate due to the low likelihood of exploitation.
OpenCVE Enrichment
Github GHSA