A SQL injection vulnerability has been identified in code-projects Doctor Appointment System version 1.0. The flaw exists in the /contactus.php file, where manipulation of the 'firstname' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been published and is available for use by threat actors. This makes the vulnerability particularly dangerous as it lowers the bar for exploitation. The affected product is a web-based doctor appointment scheduling system. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.