PT-2026-29190 · Sourcecodester · Simple Doctors Appointment System

Dyh18

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-5180

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=login2. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5180

Affected Products

Simple Doctors Appointment System