CSRF Vulnerability in Easy!Appointments by Easy!Appointments
CVE-2026-23622

7.4HIGH

Key Information:

Vendor
CVE Published:
15 January 2026

What is CVE-2026-23622?

Easy!Appointments exhibits a vulnerability in its core security mechanisms, where the csrf_verify() function only applies CSRF protections for POST requests. This oversight allows potential attackers to exploit several state-changing operations that accept parameters via GET or $_REQUEST, leading to the possibility of an attacker forcing a victim's browser to issue malicious GET requests. Such exploits could result in unauthorized creation of admin accounts, changes to admin email and password, and full administrative access to the application.

Affected Version(s)

easyappointments <= 1.5.2

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.