<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:easyappointments:easy\!appointments:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aeasyappointmentseasy%5Cappointments/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aeasyappointmentseasy%5Cappointments/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Easy!Appointments Booking::register</title><link>https://feed.craftedsignal.io/briefs/2026-10-easy-appointments-auth-bypass/</link><pubDate>Sun, 11 Oct 2026 14:01:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-easy-appointments-auth-bypass/</guid><description>Easy!Appointments versions 1.6.0 and earlier are vulnerable to an authorization bypass allowing unauthenticated modification of appointments via the Booking::register function.</description><content:encoded><![CDATA[<p>Easy!Appointments versions 1.6.0 and earlier contain an authorization bypass vulnerability within the Booking::register() function. This flaw permits unauthenticated attackers to manipulate appointment records by supplying an appointment ID without the required management hash. By enumerating sequential appointment IDs and setting a self-asserted 'manage_mode' flag, an attacker can modify appointment details, reassign appointments to attacker-controlled accounts, and extract management hashes for further actions like cancellation or rescheduling. This vulnerability poses a significant risk to organizations using the platform for scheduling, as it allows for unauthorized data access and the disruption of business operations through the manipulation of client information and schedules.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated actors to read and modify sensitive booking data across the platform. This could result in data exfiltration of customer information, service disruption through mass appointment cancellation, or unauthorized scheduling changes, directly impacting the availability and integrity of the service for legitimate users.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Easy!Appointments to a patched version beyond 1.6.0 immediately.</li>
<li>Audit application access logs for recurring requests to the booking registration endpoint featuring sequentially incrementing ID parameters.</li>
<li>Implement stricter server-side authorization checks for all appointment modification requests to ensure that 'manage_mode' flags are verified against server-stored session data rather than client-supplied input.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>