CSRF Vulnerability in Easy!Appointments by Easy!Appointments
CVE-2026-23622
7.4HIGH
What is CVE-2026-23622?
Easy!Appointments exhibits a vulnerability in its core security mechanisms, where the csrf_verify() function only applies CSRF protections for POST requests. This oversight allows potential attackers to exploit several state-changing operations that accept parameters via GET or $_REQUEST, leading to the possibility of an attacker forcing a victim's browser to issue malicious GET requests. Such exploits could result in unauthorized creation of admin accounts, changes to admin email and password, and full administrative access to the application.
Affected Version(s)
easyappointments <= 1.5.2
