CVE-2026-23622: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-23622 is a Cross-Site Request Forgery (CSRF) protection bypass vulnerability in Easy!Appointments, a self-hosted appointment scheduling application. The flaw affects all versions through 1.5.2 and was disclosed on January 15, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.4 (High), with no patched version officially released at the time of disclosure (Github Advisory, Security Advisory).

Technical details

The root cause (CWE-352) lies in application/core/EA_Security.php::csrf_verify(), which early-returns without performing any token validation when the HTTP request method is not POST (if (strtoupper($_SERVER['REQUEST_METHOD']) !== 'POST') { return $this->csrf_set_cookie(); }). Because multiple state-changing application endpoints accept parameters via GET or PHP's $_REQUEST superglobal, an attacker can bypass CSRF protection entirely by crafting a GET request. Confirmed vulnerable endpoints include index.php/admins/store (create admin), index.php/admins/update (modify admin), and index.php/account/save (change account/password). Exploitation requires no privileges and only passive user interaction — the victim must visit an attacker-controlled page while authenticated as an administrator (Security Advisory, Vulnerable Code).

Impact

Successful exploitation allows an attacker to create new administrative accounts, modify existing administrator email addresses and passwords (enabling password reset abuse), and achieve full administrative account takeover of the Easy!Appointments instance. All application data — including customer records, appointment details, and service configurations — becomes accessible to the attacker. The impact spans confidentiality, integrity, and availability, as a compromised admin account grants unrestricted control over the application (Security Advisory, Github Advisory).

Exploitability

A proof-of-concept exploit (HTML files demonstrating CSRF-based admin account creation and email modification, along with a video demonstration) was published alongside the advisory on January 15, 2026. The CVSS v4.0 exploit maturity is rated "Proof of Concept." The EPSS score is approximately 0.019% (3rd percentile), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time. No threat actor attribution has been reported (Github Advisory, Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Easy!Appointments instances running version 1.5.2 or earlier using search engines, Shodan, or Censys. Confirm the version via the application's setup page or HTTP response headers.
  2. Craft malicious payload: Create an HTML page containing an <img> tag or auto-loading <script> that issues a GET request to the target's admin endpoint with attacker-controlled parameters, e.g.:
    <img src="https://target.example.com/index.php/admins/store?first_name=Evil&last_name=Admin&email=attacker@evil.com&password=P@ssw0rd&role=admin" style="display:none">
  3. Host the malicious page: Deploy the crafted HTML on an attacker-controlled server accessible to the victim.
  4. Deliver the link: Trick an authenticated Easy!Appointments administrator into visiting the malicious page via phishing email, social engineering, or a malicious link embedded in a forum or document.
  5. CSRF bypass triggered: When the admin's browser loads the page, it automatically issues the GET request to the target application. Because csrf_verify() skips token validation for non-POST requests, the application processes the state-changing operation without any CSRF check.
  6. Account takeover: The attacker's admin account is created (or the existing admin's email/password is changed). The attacker then logs in with the newly created or modified credentials, achieving full administrative control of the Easy!Appointments instance (Security Advisory, Github Advisory).

Indicators of compromise

  • Logs: Web server access logs showing unexpected GET requests to /index.php/admins/store, /index.php/admins/update, or /index.php/account/save with admin-related query parameters (e.g., email=, password=, role=admin); requests originating from unusual referrer URLs or external domains.
  • Application: Unexpected new administrator accounts appearing in the Easy!Appointments admin panel; changes to existing administrator email addresses or passwords without corresponding legitimate user activity.
  • Network: GET requests to sensitive admin endpoints from IP addresses not associated with known administrators; unusual referrer headers in HTTP logs pointing to external or unknown domains.
  • Session/Auth: Administrator login events from unfamiliar IP addresses or geographic locations shortly after a CSRF attack window; password reset emails triggered for admin accounts without administrator-initiated requests (Security Advisory).

Mitigation and workarounds

As of the advisory publication date (January 15, 2026), no official patched version was listed; however, the Easy!Appointments repository has since released version 1.6.0 (May 27, 2026), and users should upgrade to the latest available version. As an immediate workaround, modify application/core/EA_Security.php::csrf_verify() to remove the early-return for non-POST methods, enforcing CSRF token validation for all HTTP methods. For a stricter approach, require a valid CSRF token for all requests unless the URI is explicitly whitelisted in csrf_exclude_uris. Long-term remediation should include updating all state-changing controllers to accept only POST/PUT/DELETE methods, setting SameSite, Secure, and HttpOnly cookie flags, and requiring re-authentication for sensitive operations such as email or password changes (Security Advisory, Github Advisory).

Community reactions

The vulnerability was reported by researchers faroukn and Stolichnayer and published directly through the Easy!Appointments GitHub repository's security advisory process. The advisory was reviewed and acknowledged by the project maintainer (alextselegidis). No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified at this time (Security Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management