Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-50455

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Alex Tselegidis EasyAppointments <= 1.5.1 版本的 /customers/search 接口中,order_by 参数存在 SQL 注入漏洞。该漏洞源于未经验证和过滤的用户输入被直接传入 CodeIgniter 查询构建器(Query Builder)的 order_by 方法,从而导致攻击者可执行基于时间的盲注查询,并枚举数据库结构信息。在某些 MySQL 配置下,此漏洞还可能通过 INTO OUTFILE 写入 PHP 后门文件,进而实现远程代码执行(RCE)。

AI Predicted 9.8 Difficulty: Easy EPSS 0.55% · P44

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-50455

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2025-50455

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-50455

登录查看更多情报信息。

Vendor Advisories for CVE-2025-50455 (1)

Proof of Concept for CVE-2025-50455 (1)

Security Blog Posts for CVE-2025-50455 (1)

Same Patch Batch · n/a · 2026-07-27 · 11 CVEs total

CVE-2026-51077 DesDev DedeCMS 安全漏洞
CVE-2026-51078 dedecms 安全漏洞
CVE-2026-51564 giuliopanda Milk admin 安全漏洞
CVE-2021-32084 Quest KACE Systems Deployment Appliance 安全漏洞
CVE-2021-32088 Quest KACE Systems Deployment Appliance 安全漏洞
CVE-2021-32086 Quest KACE Systems Deployment Appliance 安全漏洞
CVE-2021-32087 Quest KACE Systems Deployment Appliance 安全漏洞
CVE-2021-32085 Quest KACE Systems Deployment Appliance 安全漏洞
CVE-2026-51565 giuliopanda Milk admin 安全漏洞
CVE-2025-63913 RISC-V Open Source Supervisor Binary Interface 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-50455

No comments yet


Leave a comment