← Terug naar overzicht

A SQL injection vulnerability has been identified in code-projects Doctor Appointment System version 1.0. The flaw exists in the /contactus.php file, where manipulation of the 'firstname' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been published and is available for use by threat actors. This makes the vulnerability particularly dangerous as it lowers the bar for exploitation. The affected product is a web-based doctor appointment scheduling system. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.

Affected products

  • code-projects Doctor Appointment System 1.0

Related CVE's

  • CVE-2026-85403

Categories

  • Database & Storage
  • Web Technologies