
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23622 is a Cross-Site Request Forgery (CSRF) protection bypass vulnerability in Easy!Appointments, a self-hosted appointment scheduling application. The flaw affects all versions through 1.5.2 and was disclosed on January 15, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.4 (High), with no patched version officially released at the time of disclosure (Github Advisory, Security Advisory).
The root cause (CWE-352) lies in application/core/EA_Security.php::csrf_verify(), which early-returns without performing any token validation when the HTTP request method is not POST (if (strtoupper($_SERVER['REQUEST_METHOD']) !== 'POST') { return $this->csrf_set_cookie(); }). Because multiple state-changing application endpoints accept parameters via GET or PHP's $_REQUEST superglobal, an attacker can bypass CSRF protection entirely by crafting a GET request. Confirmed vulnerable endpoints include index.php/admins/store (create admin), index.php/admins/update (modify admin), and index.php/account/save (change account/password). Exploitation requires no privileges and only passive user interaction — the victim must visit an attacker-controlled page while authenticated as an administrator (Security Advisory, Vulnerable Code).
Successful exploitation allows an attacker to create new administrative accounts, modify existing administrator email addresses and passwords (enabling password reset abuse), and achieve full administrative account takeover of the Easy!Appointments instance. All application data — including customer records, appointment details, and service configurations — becomes accessible to the attacker. The impact spans confidentiality, integrity, and availability, as a compromised admin account grants unrestricted control over the application (Security Advisory, Github Advisory).
A proof-of-concept exploit (HTML files demonstrating CSRF-based admin account creation and email modification, along with a video demonstration) was published alongside the advisory on January 15, 2026. The CVSS v4.0 exploit maturity is rated "Proof of Concept." The EPSS score is approximately 0.019% (3rd percentile), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time. No threat actor attribution has been reported (Github Advisory, Security Advisory).
<img> tag or auto-loading <script> that issues a GET request to the target's admin endpoint with attacker-controlled parameters, e.g.:<img src="https://target.example.com/index.php/admins/store?first_name=Evil&last_name=Admin&email=attacker@evil.com&password=P@ssw0rd&role=admin" style="display:none">csrf_verify() skips token validation for non-POST requests, the application processes the state-changing operation without any CSRF check./index.php/admins/store, /index.php/admins/update, or /index.php/account/save with admin-related query parameters (e.g., email=, password=, role=admin); requests originating from unusual referrer URLs or external domains.As of the advisory publication date (January 15, 2026), no official patched version was listed; however, the Easy!Appointments repository has since released version 1.6.0 (May 27, 2026), and users should upgrade to the latest available version. As an immediate workaround, modify application/core/EA_Security.php::csrf_verify() to remove the early-return for non-POST methods, enforcing CSRF token validation for all HTTP methods. For a stricter approach, require a valid CSRF token for all requests unless the URI is explicitly whitelisted in csrf_exclude_uris. Long-term remediation should include updating all state-changing controllers to accept only POST/PUT/DELETE methods, setting SameSite, Secure, and HttpOnly cookie flags, and requiring re-authentication for sensitive operations such as email or password changes (Security Advisory, Github Advisory).
The vulnerability was reported by researchers faroukn and Stolichnayer and published directly through the Easy!Appointments GitHub repository's security advisory process. The advisory was reviewed and acknowledged by the project maintainer (alextselegidis). No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified at this time (Security Advisory).
csrf_verify() function in EA_Security.phpSource: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."