A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_action.php. Such manipulation of the argument patient_id leads to sql injection.
The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Unguardable Online_Doctor_Appointment_System
cpe:2.3:a:unguardable:online_doctor_appointment_system:1.0:*:*:*:*:*:*:*
|
— | — |