Alex Tselegidis Easy!Appointments是Alex Tselegidis个人开发者的一个在线预约系统。 Alex Tselegidis Easy!Appointments 1.6.0之前版本存在服务端请求伪造漏洞,该漏洞源于Caldav::connect_to_server函数在处理请求的caldav_url时未进行scheme或host验证,可能导致登录的后端用户访问部署网络上的回环、RFC1918和link-local主机,并引发服务端请求伪造(SSRF)漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| alextselegidis | easyappointments | < 1.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| alextselegidis | easyappointments | < 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55651 | 7.1 HIGH | Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure |
| CVE-2026-52837 | 6.9 MEDIUM | Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page |
| CVE-2026-52839 | 3.3 LOW | Easy!Appointments appointments/store and appointments/update allow cross-provider appointm |
| CVE-2026-52841 | 3.1 LOW | Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend |
| CVE-2026-52838 | 2.6 LOW | Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — St |
No comments yet