Sourcecodester · Sourcecodester Doctors Appointment System · CVE-2025-4818
Name of the Vulnerable Software and Affected Versions:
SourceCodester Doctor's Appointment System version 1.0
Description:
A critical issue affects the processing of the file /admin/delete-doctor.php, specifically the GET Parameter Handler component. The manipulation of the `ID` argument leads to SQL injection. This issue can be exploited remotely.
Recommendations:
For SourceCodester Doctor's Appointment System version 1.0, consider disabling the `delete-doctor.php` file or restricting access to it until a patch is available. Avoid using the `ID` parameter in the `/admin/delete-doctor.php` endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.