B
今週中
EasyAppointments 1.5.1 以下のバージョンにおいて、ブラインドSQLインジェクションの脆弱性
📌 一言でいうと
EasyAppointments 1.5.1 以下のバージョンにおいて、ブラインドSQLインジェクションの脆弱性が発見されました。`/index.php/customers/search` エンドポイントの `order_by` パラメータが適切にサニタイズされていないため、攻撃者はデータベースから任意の情報を抽出できる可能性があります。この脆弱性は、CodeIgniter 3のクエリビルダーの仕様を悪用してバックティックによるエスケープを回避することで発生します。
🔍該当判定
- 予約管理システム「EasyAppointments」を自社サーバーやクラウドで利用している
- EasyAppointmentsのバージョンが 1.5.1 以前である
- EasyAppointmentsの管理画面(バックエンド)にログインできるユーザーが存在する
上記いずれにも該当しない → 静観でOK
✅該当時の対応
最新バージョンへのアップデートを検討し、入力値のバリデーションおよびサニタイズを徹底してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】EasyAppointments CVE-2025-50455 対応について
お疲れさまです。EasyAppointmentsの脆弱性に関する情報共有です。
■ 概要
EasyAppointments <= 1.5.1 において、ブラインドSQLインジェクションの脆弱性 (CVE-2025-50455) が報告されました。`/index.php/customers/search` の `order_by` パラメータを悪用し、Boolean-based または Time-based の手法でデータベース内の情報を抽出される恐れがあります。
■ 影響範囲
- 対象製品: EasyAppointments
- 対象バージョン: 1.5.1 以下のすべてのバージョン
■ 対応手順
1. 自社環境で EasyAppointments を利用しているか確認してください。
2. 利用している場合は、最新のセキュリティパッチが適用されたバージョンへのアップデートを実施してください。
3. WAF等の導入により、不自然なSQL構文を含むリクエストを遮断する設定を検討してください。
■ 参考情報
- Exploit-DB EDB-ID: 52667
- CVE-2025-50455
対応優先度: 高
対応期限: 速やかに
お疲れさまです。EasyAppointmentsの脆弱性に関する情報共有です。
■ 概要
EasyAppointments <= 1.5.1 において、ブラインドSQLインジェクションの脆弱性 (CVE-2025-50455) が報告されました。`/index.php/customers/search` の `order_by` パラメータを悪用し、Boolean-based または Time-based の手法でデータベース内の情報を抽出される恐れがあります。
■ 影響範囲
- 対象製品: EasyAppointments
- 対象バージョン: 1.5.1 以下のすべてのバージョン
■ 対応手順
1. 自社環境で EasyAppointments を利用しているか確認してください。
2. 利用している場合は、最新のセキュリティパッチが適用されたバージョンへのアップデートを実施してください。
3. WAF等の導入により、不自然なSQL構文を含むリクエストを遮断する設定を検討してください。
■ 参考情報
- Exploit-DB EDB-ID: 52667
- CVE-2025-50455
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] EasyAppointments CVE-2025-50455
Dear IT Administration Team,
We are sharing information regarding a vulnerability in EasyAppointments.
■ Overview
A blind SQL injection vulnerability (CVE-2025-50455) has been identified in EasyAppointments <= 1.5.1. An attacker can exploit the `order_by` parameter at the `/index.php/customers/search` endpoint to extract sensitive data from the database using Boolean or Time-based techniques.
■ Scope
- Product: EasyAppointments
- Affected Versions: <= 1.5.1
■ Mitigation Steps
1. Verify if EasyAppointments is deployed within the corporate environment.
2. Update the software to the latest patched version immediately.
3. Consider implementing WAF rules to detect and block malicious SQL injection patterns.
■ Reference
- Exploit-DB EDB-ID: 52667
- CVE-2025-50455
Priority: High
Deadline: Immediate
Dear IT Administration Team,
We are sharing information regarding a vulnerability in EasyAppointments.
■ Overview
A blind SQL injection vulnerability (CVE-2025-50455) has been identified in EasyAppointments <= 1.5.1. An attacker can exploit the `order_by` parameter at the `/index.php/customers/search` endpoint to extract sensitive data from the database using Boolean or Time-based techniques.
■ Scope
- Product: EasyAppointments
- Affected Versions: <= 1.5.1
■ Mitigation Steps
1. Verify if EasyAppointments is deployed within the corporate environment.
2. Update the software to the latest patched version immediately.
3. Consider implementing WAF rules to detect and block malicious SQL injection patterns.
■ Reference
- Exploit-DB EDB-ID: 52667
- CVE-2025-50455
Priority: High
Deadline: Immediate