Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Vulnerability Description
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`) without authentication and without field whitelisting. Anyone in possession of the 12-character `appointment_hash` — which appears in plain text in reschedule emails, confirmation page URLs, and operator-side calendar links — can read every column of that customer's row in the `ea_users` table. Version 1.6.0 contains a patch.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Alex Tselegidis Easy!Appointments 信息泄露漏洞
Vulnerability Description
Alex Tselegidis Easy!Appointments是Alex Tselegidis个人开发者的一个在线预约系统。 Alex Tselegidis Easy!Appointments 1.5.2及之前版本存在安全漏洞,该漏洞源于预订重新安排视图将完整的客户记录嵌入为内联JavaScript,未进行身份验证和字段白名单过滤,导致任何拥有12字符appointment_hash的人均可读取ea_users表中该客户行的所有列。
CVSS Information
N/A
Vulnerability Type
N/A