Impact
In Easy!Appointments version 1.5.2 the customers search endpoint reveals appointment hashes for all users when accessed by an authenticated user. Those identifiers can be used to edit an a classic data exposure flaw (CWE‑200) that compromises the confidentiality, integrity, and availability of the appointment scheduling service.
Affected Systems
The affected product is Easy!Appointments 1.5.2, released by alextselegidis. Version 1.6 fix.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1 The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker only needs to be an authenticated user to trigger the excessive data exposure; the attack vector is therefore local to the application layer. Once the hashes are obtained, the attacker can modify or delete other users’ appointments, resulting in service disruption and potential revenue loss.
OpenCVE Enrichment
Github GHSA