THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xgr6-pqjv-3pf8 (medium) — Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

[GHSA] GHSA-xgr6-pqjv-3pf8 (medium) — Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

medgithub_advisoriesPublished 2026-07-29

GHSA-xgr6-pqjv-3pf8 Severity: medium CVE: CVE-2026-52837

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

## Summary

The booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the **entire customer record** as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`) without authenti

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xgr6-pqjv-3pf8