PT-2021-17390 · Unknown · Doctor Appointment System

Published

2021-03-04

·

Updated

2021-03-05

·

CVE-2021-27314

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions doctor appointment system version 1.0
Description The issue allows an unauthenticated attacker to insert malicious SQL queries via the username parameter at the login page. This is due to a SQL injection flaw in the admin.php file of the doctor appointment system.
Recommendations For doctor appointment system version 1.0, consider restricting access to the admin.php file until a patch is available. As a temporary workaround, avoid using the username parameter in the login page to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27314

Affected Products

Doctor Appointment System