CPE
Easy!Appointments versions 1.6.0 and earlier are vulnerable to an authorization bypass allowing unauthenticated modification of appointments via the Booking::register function.