VYPR

Easyappointments

by Alextselegidis

Source repositories

CVEs (2)

  • CVE-2023-3285HigJul 9, 2024
    risk 0.50cvss 7.7epss 0.00

    A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation.

  • CVE-2025-50383Aug 25, 2025
    risk 0.00cvss epss 0.00

    alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.