Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52837— Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

AI Predicted 6.5 Difficulty: Easy EPSS 0.35% · P28

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProductVersion RangeStatus
alextselegidiseasyappointments< 1.6.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-52837

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Source: NVD (National Vulnerability Database)
Vulnerability Description
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`) without authentication and without field whitelisting. Anyone in possession of the 12-character `appointment_hash` — which appears in plain text in reschedule emails, confirmation page URLs, and operator-side calendar links — can read every column of that customer's row in the `ea_users` table. Version 1.6.0 contains a patch.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Alex Tselegidis Easy!Appointments 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Alex Tselegidis Easy!Appointments是Alex Tselegidis个人开发者的一个在线预约系统。 Alex Tselegidis Easy!Appointments 1.5.2及之前版本存在安全漏洞,该漏洞源于预订重新安排视图将完整的客户记录嵌入为内联JavaScript,未进行身份验证和字段白名单过滤,导致任何拥有12字符appointment_hash的人均可读取ea_users表中该客户行的所有列。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
alextselegidiseasyappointments < 1.6.0 -

II. Public POCs for CVE-2026-52837

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52837

登录查看更多情报信息。

Patches & Fixes for CVE-2026-52837 (2)

Vendor Advisories for CVE-2026-52837 (1)

Same Patch Batch · alextselegidis · 2026-07-14 · 6 CVEs total

CVE-2026-556517.1 HIGHEasy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
CVE-2026-528393.3 LOWEasy!Appointments appointments/store and appointments/update allow cross-provider appointm
CVE-2026-528413.1 LOWEasy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend
CVE-2026-528402.7 LOWEasy!Appointments has server-side request forgery in CalDAV connection test that exposes t
CVE-2026-528382.6 LOWEasy!Appointments disable_booking_message rendered as raw HTML on public booking page — St

IV. Related Vulnerabilities

V. Comments for CVE-2026-52837

No comments yet


Leave a comment