First published: Wed May 07 2025(Updated: )
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Easy!Appointments | ||
composer/alextselegidis/easyappointments | <=1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29448 is classified as a Denial of Service (DoS) vulnerability.
CVE-2025-29448 is caused by a booking logic flaw that allows unauthenticated attackers to create appointments with excessively long durations.
To fix CVE-2025-29448, upgrade Easy Appointments to a version beyond 1.5.1 where the vulnerability has been addressed.
CVE-2025-29448 affects users of Easy Appointments version 1.5.1.
Attackers can leverage CVE-2025-29448 to cause a denial of service by manipulating appointment durations.