PT-2025-14817 · Unknown · Projectworlds Online Doctor Appointment Booking System

Pkey

·

Published

2025-04-03

·

Updated

2025-04-04

·

CVE-2025-3185

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions projectworlds Online Doctor Appointment Booking System version 1.0
Description A critical issue was discovered in the projectworlds Online Doctor Appointment Booking System, affecting an unknown function of the file /patient/patientupdateprofile.php. The manipulation of the patientFirstName argument leads to SQL injection. This issue can be exploited remotely. The exploit has been publicly disclosed and may be used. Other parameters might also be affected.
Recommendations For projectworlds Online Doctor Appointment Booking System version 1.0, consider disabling the patientupdateprofile.php file or restricting access to it until a patch is available. Avoid using the patientFirstName argument in the affected API endpoint until the issue is resolved. As a temporary workaround, restrict access to the /patient/patientupdateprofile.php endpoint to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-3185

Affected Products

Projectworlds Online Doctor Appointment Booking System