CVE-2025-50383: SQL Injection
Published Aug 25, 2025
·Updated
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the orderby parameter.
Affected Software
3 affected componentsFixes available
alextselegidis Easy!Appointments
composer/alextselegidis/easyappointments<1.5.2-beta.1
1.5.2-beta.1
EasyAppointments Easy\!appointments=1.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/alextselegidis/easyappointmentsto a version that resolves this vulnerability.Fixed in 1.5.2-beta.1
Event History
Aug 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
Description
Data Sourced
via NVD·06:15 PM
SeverityWeaknessAffected Software
Aug 26, 2025
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50383?
CVE-2025-50383 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2025-50383?
To fix CVE-2025-50383, upgrade to Easy!Appointments version 1.5.2-beta.1 or later.
3
What is the impact of CVE-2025-50383?
The impact of CVE-2025-50383 can lead to unauthorized access to the database, affecting the integrity of the application.
4
Which versions of Easy!Appointments are affected by CVE-2025-50383?
Easy!Appointments version 1.5.1 is affected by CVE-2025-50383.
5
Is CVE-2025-50383 exploited in the wild?
There are currently no public reports indicating that CVE-2025-50383 is actively being exploited in the wild.