Loading HuntDB...

GHSA-7f62-4887-cfv5

GitHub Security Advisory

Privilege escalation in easyappointments

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

The Easy!Appointments API authorization is checked against the user's existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the "/api/v1/admins/" endpoint and take over the system. A [patch](https://github.com/alextselegidis/easyappointments/commit/63dbb51decfcc1631c398ecd6d30e3a337845526) is available on the `develop` branch of the repository.

Affected Packages

Packagist alextselegidis/easyappointments
Affected versions: 0 (last affected: 1.4.3)

Related CVEs

Key Information

GHSA ID
GHSA-7f62-4887-cfv5
Published
May 11, 2022 12:01 AM
Last Modified
May 25, 2022 7:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
alextselegidis/easyappointments
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.