← Terug naar overzicht

A SQL injection vulnerability has been discovered in code-projects Doctor Appointment System version 1.0. The flaw exists in the /contactus.php file, where manipulation of the 'firstname' argument allows for SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been published and is available for use, increasing the risk of active exploitation. The affected product is a PHP-based web application used for managing doctor appointments. The issue was assigned CVE-2026-85403 and is tracked in the NVD and VulDB databases.

Affected products

  • code-projects Doctor Appointment System 1.0

Related CVE's

  • CVE-2026-85403

Categories

  • Database & Storage
  • Web Technologies