VDB
Sign up
MEDIUM

GHSA-2f28-69j7-85hf

Easy!Appointments SQL injection vulnerability

Quick fix

GHSA-2f28-69j7-85hf — alextselegidis/easyappointments: upgrade to the fixed version with the command below.

composer require alextselegidis/easyappointments:^1.5.2-beta.1

Details

alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/alextselegidis/easyappointments
Introduced in: 0Fixed in: 1.5.2-beta.1
Fixcomposer require alextselegidis/easyappointments:^1.5.2-beta.1

References