PT-2025-52410 · Unknown · Online Appointment Booking System

Wesec

·

Published

2025-12-19

·

Updated

2025-12-24

·

CVE-2025-14939

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Appointment Booking System version 1.0
Description A flaw exists in the Online Appointment Booking System that allows for SQL injection. The issue is located in the /admin/deletemanager.php file, specifically through manipulation of the managername argument. This allows for remote exploitation. The details of the exploit have been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-14939

Affected Products

Online Appointment Booking System