Bounties
Partners
Community
Info
alextselegidis / easyappointments
Project repository
:date: Easy!Appointments - Self Hosted Appointment Scheduler
Submit a report
FIRST INTERACTION
WITHIN
141 DAYS
REVIEW
WITHIN
141 DAYS
FIX
WITHIN
65 DAYS
Unverified password change : old password can be used as new password
Jan 12th 2024
th3l0newolf
•
informative
Medium
Unverified Password Change
Jan 12th 2024
newb3ast
•
informative
Medium
IDOR change Personal Information in settings
Jan 12th 2024
meme-dm
•
duplicate
High
XSS & SQL Injection on "zip_code" parameter
Jan 12th 2024
xo19do
•
duplicate
High
Insufficient Session Expiration allows the old session to be valid after logging...
Jan 12th 2024
me0x2gg
•
informative
Medium
Stored HTML Injection on Service
Jan 12th 2024
si13ntr311ik
•
informative
Medium
SQL Injection
Jan 12th 2024
deepakkuma24
•
informative
High
Sensitive Information Disclosed likes hash, password etc
Jan 12th 2024
deepakkuma24
•
informative
Medium
Insecure direct object references (IDOR)
Jan 12th 2024
deepakkuma24
•
informative
High
IDOR can make attackers add or close others' unavaiable
Jul 17th 2023
lujiefsi
•
Medium
Medium
•
CVE-2023-3700
CVE-2023-3700
Privilege Escalation Lead to full control on the Organization
Jan 12th 2024
mohamedabdelhady933
•
informative
High
Authenticated user without any privileges can read and modify calendar appointme...
Jan 12th 2024
thelabda
•
informative
Medium
User Can edit Customers even after logout from the application
Jan 12th 2024
mohitkumar0786
•
informative
Medium
Improper Authorization lead an low privilege user can create appointment in Admi...
Jan 12th 2024
baobaovt
•
informative
Critical
Information Disclosure
Jan 12th 2024
duyhm1995
•
informative
None
Reflected XSS
Jan 12th 2024
m0ck3d
•
informative
Medium
Stored XSS in Personal Information Feature (First & Last Name)
Jan 12th 2024
raihansmart
•
informative
Medium
Moment 2.25.3 in use which is vulnerable to CVE-2022-31129
Jan 12th 2024
popcorn94
•
informative
Medium
No Protection Against Bruteforce attacks on Login Page
Apr 25th 2023
m0ck3d
•
self closed
Stored XSS
Apr 20th 2023
m0ck3d
•
self closed
Stored XSS
Apr 15th 2023
liteshghute
•
Medium
Medium
•
CVE-2023-2102
CVE-2023-2102
Multiple XSS in Create/Update Funtion Version 1.4.3 and 1.5.0-dev.2
Apr 15th 2023
tht1997
•
Medium
Medium
•
CVE-2023-2103
CVE-2023-2103
Html Injection to Open redirect
Apr 5th 2023
ghostbit11
•
High
High
Improper Access Control which allows one provider to view and edit others provid...
Apr 15th 2023
hacker1984
•
Medium
Medium
•
CVE-2023-2104
CVE-2023-2104
Session Fixation Vulnerability
Apr 15th 2023
hacker1984
•
Medium
Medium
•
CVE-2023-2105
CVE-2023-2105
Privilege Escalation Lead to full control on the Organization
Mar 27th 2023
mohamedabdelhady933
•
informative
High
Full Account TakeOver
Mar 27th 2023
mohamedabdelhady933
•
informative
High
Weak Password Policy
Mar 27th 2023
ctflearner
•
informative
High
Stored XSS When Adding Categories leads to Defacement
Mar 13th 2023
gonzxph
•
informative
Medium
Stored HTML Injection via Company Name
Mar 13th 2023
mike993
•
Medium
Medium
•
CVE-2023-1367
CVE-2023-1367
Stored HTML&Hyperlink injection via first and last name field
Mar 2nd 2023
thewhiteevil
•
informative
Medium
Default account creation on all installation methods
Mar 8th 2023
pedrojosenavasperez
•
Medium
Medium
•
CVE-2023-1269
CVE-2023-1269
database credentials disclose in github repo source code
Mar 1st 2023
wickrine
•
not applicable
Composer installed.json publicly accessible
Mar 1st 2023
nilabhrajpoot
•
informative
High
UI REDRESSING
Mar 8th 2023
tharunavula
•
Critical
Critical
Administrative Account Takeover
Mar 8th 2023
galapag0s
•
duplicate
High
Account Takeover
Mar 8th 2023
gaurav-g2
•
Medium
Medium
Broken access control lead to information disclosure
Mar 13th 2023
gaurav-g2
•
informative
High
API Privilege Escalation
May 9th 2022
francescocarlucci
•
High
•
$15
High
•
$15
•
CVE-2022-1397
CVE-2022-1397
DoS due to unrestricted hashing
May 9th 2022
francescocarlucci
•
High
•
$15
High
•
$15
Exposure of Private Personal Information to an Unauthorized Actor
Mar 8th 2022
francescocarlucci
•
Critical
•
$35
Critical
•
$35
•
CVE-2022-0482
CVE-2022-0482
Cross-site Scripting (XSS) - Stored
Mar 13th 2023
0x7zed
•
informative
High
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Jun 6th 2022
0x7zed
•
not applicable
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Jun 6th 2022
dmandefy
•
not applicable
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0