Itsourcecode · Online Doctor Appointment System · CVE-2026-3980
**Name of the Vulnerable Software and Affected Versions**
itsourcecode Online Doctor Appointment System version 1.0
**Description**
A security issue exists in itsourcecode Online Doctor Appointment System 1.0. The issue affects an unknown function within the `/admin/patient action.php` file. Manipulation of the `patient id` argument can lead to SQL injection. The attack can be initiated remotely, and the exploit has been publicly disclosed.
**Recommendations**
versions prior to 1.0