Alex Tselegidis
18 exploits
Active since Mar 2022
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Easy!Appointments < 1.6.0 - Cross-Provider Appointment Authorization Bypass
CVSS 3.3
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Easy!Appointments < 1.6.0 - Stored Cross-Site Scripting
CVSS 2.6
Easy!Appointments < 1.6.0 - Cross-Provider Appointment Authorization Bypass
CVSS 3.3
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
CVSS 2.7
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
CVSS 3.1
Plainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)
CVSS 8.3
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
easyappointments < 1.5.0 - Use of Hard-coded Credentials
CVSS 9.8
easyappointments < 1.5.0 - Code Injection
CVSS 3.8
GitHub alextselegidis/easyappointments <1.5.0 - XSS
CVSS 4.8
GitHub alextselegidis/easyappointments <1.5.0 - XSS
CVSS 5.4
alextselegidis/easyappointments <1.5.0 - Info Disclosure
CVSS 5.4
alextselegidis/easyappointments <1.5.0 - Info Disclosure
CVSS 8.8
alextselegidis/easyappointments <1.5.0 - Open Redirect
CVSS 6.3
easyappointments < 1.5.0 - Authorization Bypass Through User-Controlled Key
CVSS 6.3