{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aeasyappointmentseasyappointments/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2025-50455"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["EasyAppointments (\u003c= 1.5.1)"],"_cs_severities":["high"],"_cs_tags":["webapps","sqli","cve-2025-50455"],"_cs_type":"advisory","_cs_vendors":["EasyAppointments"],"content_html":"\u003cp\u003eEasyAppointments versions 1.5.1 and earlier are affected by a blind SQL injection vulnerability (CVE-2025-50455) within the 'order_by' parameter processed by the application's search endpoints, including '/index.php/customers/search', '/index.php/admins/search', and others. The vulnerability exists because the CodeIgniter 3 framework's Query Builder 'order_by' function fails to adequately sanitize input, specifically allowing parenthesized subqueries to bypass identifier protection mechanisms. An authenticated attacker can leverage this flaw to perform both boolean-based and time-based data exfiltration. Successful exploitation allows an attacker to enumerate database tables, columns, user email addresses, and account password hashes. The vulnerability was disclosed alongside a functional Proof of Concept (PoC) script, significantly increasing the risk of exploitation for unpatched instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to the application login page at /index.php/login to obtain a CSRF token.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates as a user by sending a POST request to /index.php/login/validate with valid credentials and a valid CSRF token.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a vulnerable search endpoint, such as /index.php/customers/search, which accepts the 'order_by' parameter.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious 'order_by' parameter containing a SQL subquery (e.g., using 'SLEEP()' for time-based or 'IF' for boolean-based inference).\u003c/li\u003e\n\u003cli\u003eThe application backend processes the unsanitized 'order_by' parameter through the CodeIgniter 3 Query Builder.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL, causing the application to return different responses or introduce time delays based on the boolean result of the subquery.\u003c/li\u003e\n\u003cli\u003eAttacker systematically iterates through bits or characters of target database fields to exfiltrate sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the full extraction of database contents. Targeted data includes administrator credentials, system configuration details, and user personally identifiable information (PII). In environments with misconfigured 'secure_file_priv' settings, the vulnerability could potentially be escalated to local file read or arbitrary file write, posing a severe risk of unauthorized access to the underlying Linux host.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to a version of EasyAppointments where CVE-2025-50455 is addressed.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all application parameters that influence SQL query construction.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to detect and block HTTP POST requests containing SQL syntax keywords (e.g., SELECT, SLEEP, IF, ORDER BY) in the 'order_by' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous time-delayed responses (e.g., latency exceeding 5 seconds) to requests directed at the identified search endpoints.\u003c/li\u003e\n\u003cli\u003eAudit database user permissions to ensure the application user follows the principle of least privilege, specifically restricting access to 'information_schema' and file system operations.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T14:31:59Z","date_published":"2026-09-01T14:31:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-easyappointments-sqli/","summary":"EasyAppointments versions 1.5.1 and earlier contain a blind SQL injection vulnerability in search endpoints that allows authenticated attackers to extract sensitive database content via malicious 'order_by' parameters.","title":"Blind SQL Injection in EasyAppointments","url":"https://feed.craftedsignal.io/briefs/2026-09-easyappointments-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:easyappointments:easyappointments:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}