Sourcecodester · Doctor Appointment System · CVE-2026-9603
**Name of the Vulnerable Software and Affected Versions**
SourceCodester eDoc Doctor Appointment System version 1.0
**Description**
An issue exists in the '/admin/delete-session.php' endpoint where manipulation of the `ID` argument leads to missing authorization. This allows for remote exploitation of the system.
**Recommendations**
Update SourceCodester eDoc Doctor Appointment System version 1.0 to a patched version.
As a temporary workaround, restrict access to the '/admin/delete-session.php' file to minimize the risk of exploitation.