GHSA-7f62-4887-cfv5
GitHub Security Advisory
Privilege escalation in easyappointments
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The Easy!Appointments API authorization is checked against the user's existence, without validating the permissions. As a result, a low privileged user (eg. provider) can create a new admin user via the "/api/v1/admins/" endpoint and take over the system. A [patch](https://github.com/alextselegidis/easyappointments/commit/63dbb51decfcc1631c398ecd6d30e3a337845526) is available on the `develop` branch of the repository.
Affected Packages
Packagist
alextselegidis/easyappointments
Affected versions:
0
(last affected: 1.4.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.