Описание
A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argument appointment_id results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Ссылки
- ExploitThird Party Advisory
- Product
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:unguardable:online_doctor_appointment_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.00027
Низкий
4.7 Medium
CVSS3
9.8 Critical
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-74
CWE-89
Связанные уязвимости
CVSS3: 4.7
github
21 день назад
A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argument appointment_id results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
EPSS
Процентиль: 8%
0.00027
Низкий
4.7 Medium
CVSS3
9.8 Critical
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-74
CWE-89