MEDIUM
GHSA-2f28-69j7-85hf
Easy!Appointments SQL injection vulnerability
Quick fix
GHSA-2f28-69j7-85hf — alextselegidis/easyappointments: upgrade to the fixed version with the command below.
composer require alextselegidis/easyappointments:^1.5.2-beta.1Details
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/alextselegidis/easyappointments
Introduced in:
0Fixed in: 1.5.2-beta.1Fix
composer require alextselegidis/easyappointments:^1.5.2-beta.1References
- https://nvd.nist.gov/vuln/detail/CVE-2025-50383[ADVISORY]
- https://github.com/alextselegidis/easyappointments/commit/0f0d71cfe0692daed9aee59bc424ce2a084fd59e[WEB]
- https://easyappointments.org[WEB]
- https://github.com/Abdullah4eb/CVE-2025-50383[WEB]
- https://github.com/alextselegidis/easyappointments[PACKAGE]
- https://github.com/alextselegidis/easyappointments/releases/tag/1.5.2-beta.1[WEB]