Vulnerability Details CVE-2026-23622
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or $_REQUEST), so an attacker can perform CSRF by forcing a victim's browser to issue a crafted GET request. Impact: creation of admin accounts, modification of admin email/password, and full admin account takeover.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-23622
-
cpe:2.3:a:easyappointments:easy!appointments:0.1.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.2.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.3.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.4.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.5.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.6.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.7.0
-
cpe:2.3:a:easyappointments:easy!appointments:0.7.1
-
cpe:2.3:a:easyappointments:easy!appointments:1.0
-
cpe:2.3:a:easyappointments:easy!appointments:1.1.0
-
cpe:2.3:a:easyappointments:easy!appointments:1.1.1
-
cpe:2.3:a:easyappointments:easy!appointments:1.2.0
-
cpe:2.3:a:easyappointments:easy!appointments:1.2.1
-
cpe:2.3:a:easyappointments:easy!appointments:1.3.0
-
cpe:2.3:a:easyappointments:easy!appointments:1.3.1
-
cpe:2.3:a:easyappointments:easy!appointments:1.3.2
-
cpe:2.3:a:easyappointments:easy!appointments:1.4.0
-
cpe:2.3:a:easyappointments:easy!appointments:1.4.1
-
cpe:2.3:a:easyappointments:easy!appointments:1.4.2
-
cpe:2.3:a:easyappointments:easy!appointments:1.4.3
-
cpe:2.3:a:easyappointments:easy!appointments:1.5.0
-
cpe:2.3:a:easyappointments:easy!appointments:1.5.1
-
cpe:2.3:a:easyappointments:easy!appointments:1.5.2