Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus.php mysqli_query sql injection | |
| First Time appeared |
Girishsaraf
Girishsaraf online-appointment-booking-system |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:girishsaraf:online-appointment-booking-system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Girishsaraf
Girishsaraf online-appointment-booking-system |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T22:30:14.476Z
Reserved: 2026-10-05T14:58:20.097Z
Link: CVE-2026-105470
No data.
No data.
No data.
OpenCVE Enrichment
No data.