CVE-2025-29448: Input Validation
Published May 7, 2025
·Updated
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.
Affected Software
3 affected components
Easy Appointments Easy Appointments
composer/alextselegidis/easyappointments<=1.5.1
EasyAppointments Easy\!appointments=1.5.1
Remediation
Patch Available
Event History
May 7, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyAffected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-29448?
CVE-2025-29448 is classified as a Denial of Service (DoS) vulnerability.
2
What causes the vulnerability in CVE-2025-29448?
CVE-2025-29448 is caused by a booking logic flaw that allows unauthenticated attackers to create appointments with excessively long durations.
3
How do I fix CVE-2025-29448?
To fix CVE-2025-29448, upgrade Easy Appointments to a version beyond 1.5.1 where the vulnerability has been addressed.
4
Who is affected by CVE-2025-29448?
CVE-2025-29448 affects users of Easy Appointments version 1.5.1.
5
What can attackers do with CVE-2025-29448?
Attackers can leverage CVE-2025-29448 to cause a denial of service by manipulating appointment durations.