THREAT OPS › Threat News › [GHSA] GHSA-xgr6-pqjv-3pf8 (medium) — Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
[GHSA] GHSA-xgr6-pqjv-3pf8 (medium) — Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
GHSA-xgr6-pqjv-3pf8 Severity: medium CVE: CVE-2026-52837
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
## Summary
The booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the **entire customer record** as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`) without authenti
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-52837cve
- victim.disclosure@example.invalidemail
Original source: https://github.com/advisories/GHSA-xgr6-pqjv-3pf8