
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross Site Scripting (XSS) vulnerability exists in Alex Tselegidis EasyAppointments version 1.5.0. The vulnerability allows a remote attacker with authenticated access to execute arbitrary code via the legal_settings parameter (Vulnerability Report).
The vulnerability is present in the /index.php/legal_settings endpoint which contains three fields for inserting custom policies like cookie policy. The code inserted in these fields gets executed whenever the page loads, not just during display, enabling XSS attacks. The vulnerability has been assigned a CVSS score of 6.6 (Medium severity) (Vulnerability Report).
A successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary JavaScript code in the context of other users' browsers who visit the legal settings page. This could lead to cookie theft and potential account compromise (Vulnerability Report).
The recommended mitigation is to implement proper input sanitization by whitelisting allowed content. However, as of the report date, no official patch is available as the maintainer acknowledges the issue but states no fix will be issued at the moment (Vulnerability Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."