{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aeasyappointmentseasy%5Cappointments/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:easyappointments:easy\\!appointments:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Easy!Appointments (\u003c= 1.6.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Easy!Appointments"],"content_html":"\u003cp\u003eEasy!Appointments versions 1.6.0 and earlier contain an authorization bypass vulnerability within the Booking::register() function. This flaw permits unauthenticated attackers to manipulate appointment records by supplying an appointment ID without the required management hash. By enumerating sequential appointment IDs and setting a self-asserted 'manage_mode' flag, an attacker can modify appointment details, reassign appointments to attacker-controlled accounts, and extract management hashes for further actions like cancellation or rescheduling. This vulnerability poses a significant risk to organizations using the platform for scheduling, as it allows for unauthorized data access and the disruption of business operations through the manipulation of client information and schedules.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated actors to read and modify sensitive booking data across the platform. This could result in data exfiltration of customer information, service disruption through mass appointment cancellation, or unauthorized scheduling changes, directly impacting the availability and integrity of the service for legitimate users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Easy!Appointments to a patched version beyond 1.6.0 immediately.\u003c/li\u003e\n\u003cli\u003eAudit application access logs for recurring requests to the booking registration endpoint featuring sequentially incrementing ID parameters.\u003c/li\u003e\n\u003cli\u003eImplement stricter server-side authorization checks for all appointment modification requests to ensure that 'manage_mode' flags are verified against server-stored session data rather than client-supplied input.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T14:01:49Z","date_published":"2026-10-11T14:01:49Z","id":"https://feed.craftedsignal.io/briefs/2026-10-easy-appointments-auth-bypass/","summary":"Easy!Appointments versions 1.6.0 and earlier are vulnerable to an authorization bypass allowing unauthenticated modification of appointments via the Booking::register function.","title":"Authorization Bypass in Easy!Appointments Booking::register","url":"https://feed.craftedsignal.io/briefs/2026-10-easy-appointments-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:easyappointments:easy\\!appointments:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}