PT-2022-23257 · Unknown · Doctor Appointment System

Published

2022-08-31

·

Updated

2022-10-01

·

CVE-2022-36201

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Doctor’s Appointment System version 1.0
Description The issue concerns a Blind SQL Injection vulnerability. It is exploitable via the settings.php file and also through the booking.php file, where the id parameter is vulnerable.
Recommendations For Doctor’s Appointment System version 1.0, consider disabling the id parameter in the booking.php file until a patch is available. Restrict access to the settings.php and booking.php files to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-36201

Affected Products

Doctor Appointment System