A SQL injection vulnerability has been identified in code-projects Doctor Appointment System version 1.0. The flaw exists in the file /patient/booking.php, where manipulation of the doc_id argument allows an attacker to perform SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit is already available, increasing the risk of active exploitation. The affected product is a web-based doctor appointment management system. The vulnerability has been assigned CVE-2026-85402 and is tracked in multiple vulnerability databases including NVD and VulDB. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.