← Terug naar overzicht

A SQL injection vulnerability has been identified in code-projects Doctor Appointment System version 1.0. The flaw exists in the file /patient/booking.php, where manipulation of the doc_id argument allows an attacker to inject malicious SQL queries. The vulnerability can be exploited remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The attack vector is network-based, making it accessible to a wide range of threat actors. The vulnerability affects the booking functionality of the application, potentially exposing sensitive patient and doctor data. No patch details are currently mentioned in the article. The issue has been documented across multiple security databases including NVD and VulDB.

Affected products

  • code-projects Doctor Appointment System 1.0

Related CVE's

  • CVE-2026-85402

Categories

  • Database & Storage
  • Web Technologies