CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-996f-334j-67g7: Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

lowCVSS 2.6CVE-2026-52838
Summary Easy!Appointments allows administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the disable_booking_message setting via a rich-text editor and later passed directly to the public booking_message view without escaping or sanitization: <p><?= vars('message_text') ?></p> An authenticated administrator can store HTML or JavaScript in this field, enable disabled-booking mode, and trigger stored XSS in every unauthenticated visitor who opens the public booking page. Root Cause — Step by Step Code Flow Step 1 — Rich text editor value stored without sanitization The booking settings page collects the message value from the Trumbowyg rich-text editor and submits it as raw HTML: // assets/js/pages/booking_settings.js line 61-92 bookingSettings.push({ name: 'disable_booking_message', value: $disableBookingMessage.trumbowyg('html'), }); Step 2 — Settings controller saves value verbatim The backend settings controller persists the submitted value without any HTML sanitization: // application/controllers/Booking_settings.php line 76-104 $this->settings_model->save($setting); Step 3 — Public booking controller forwards stored value to view When booking is disabled, the public booking controller loads the stored message and passes it directly to the view: // application/controllers/Booking.php line 113-132 $disable_booking_message = setting('disable_booking_message'); html_vars([ 'message_text' => $disable_booking_message, ]); Step 4 — Public view renders value without escaping The booking message view emits the value raw using PHP's short echo tag with no escaping: // application/views/pages/booking_message.php line 10-12 <p><?= vars('message_text') ?></p> No htmlspecialchars(), no sanitization, no template escaping is applied at any point in this rendering path. Proof of Concept Step 1 — Store malicious disabled-booking message as admin: POST /index.php/booking_settings/save HTTP/1.1 Host: 1

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
low — CVSS 2.6
Published
2026-07-29
Last updated
2026-07-29
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-996f-334j-67g7

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-52838coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories