What is CVE-2025-50455?
A critical SQL injection vulnerability exists in the 'order_by' parameter of the '/customers/search' endpoint in Alex Tselegidis EasyAppointments version 1.5.1 and earlier. The flaw stems from unsanitized user input passed to the CodeIgniter Query Builder, allowing attackers to perform time-based database attacks. Immediate patching and WAF implementation are strongly recommended.
Azərbaycanca: Alex Tselegidis EasyAppointments 1.5.1 və daha əvvəlki versiyalarında '/customers/search' endpoint-inin 'order_by' parametrində kritik SQL injection zəifliyi aşkar edilib. Bu, CodeIgniter Query Builder-ə ötürülən təmizlənməmiş istifadəçi girişindən qaynaqlanır və təcavüzkarlara time-based sorgular vasitəsilə verilənlər bazasına müdaxilə imkanı yaradır. Dərhal ən son versiyaya yenilənmə və WAF qaydalarının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What product is affected by CVE-2025-50455?
CVE-2025-50455 affects Alex Tselegidis EasyAppointments version 1.5.1 and earlier.
How can the CVE-2025-50455 vulnerability be mitigated?
Immediate patching to the latest version and implementing WAF rules are recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.