Sceawere

Vulnerability Detail

CVE-2026-105387UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Online-Appointment-Booking-System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
girishsaraf
Product
Online-Appointment-Booking-System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T19:17:16.910Z",
  "pubdate": "2026-10-05T19:17:16.910Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in the Patient Login Handler of the girishsaraf Online-Appointment-Booking-System, affecting versions up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5.\nThe vulnerability stems from improper neutralization of special elements used in an SQL command within the cover.php file. By manipulating the 'uname' or 'psw' arguments, an unauthenticated remote attacker can inject malicious SQL queries.\nThis flaw allows unauthorized access to the backend database, potentially leading to the exposure of sensitive patient information, authentication bypass, or complete database compromise.\nAs the project utilizes a rolling release model and lacks an official vendor patch, the system remains in a vulnerable state. Given that exploit code is publicly available, the risk of exploitation by malicious actors is high. No specific authentication or complex privileges are required to initiate the attack, making it a significant threat to system integrity and data confidentiality.",
  "technicalDetails": "The root cause of the vulnerability is the usage of unsanitized user-supplied input within the mysqli_query function located in cover.php. The application fails to employ prepared statements or parameterized queries when processing the 'uname' (username) and 'psw' (password) parameters during the authentication handshake.\nThe exploitation flow begins with the attacker sending a crafted HTTP POST request to the affected login endpoint. Instead of providing standard credentials, the attacker injects SQL metacharacters (such as single quotes, comment delimiters, or UNION operators) into the 'uname' or 'psw' fields. Because the input is concatenated directly into the backend SQL string, the database management system interprets the attacker's input as executable code rather than literal data.\nBy manipulating the query structure, an attacker can effectively terminate the intended authentication statement and append arbitrary SQL commands. This allows the attacker to bypass the intended authentication mechanism, execute unauthorized SELECT queries to dump database contents, or modify/delete existing data. In environments where the database user possesses sufficient permissions, it may be possible to escalate privileges or interact with the underlying host file system.\nThe vulnerability is remotely exploitable over the network without requiring pre-existing authentication. The application's design, specifically the handler within cover.php, performs direct string concatenation, creating an injection vector. The lack of input validation or output encoding on these parameters ensures that any crafted payload is executed with the privileges of the database service account.\nPost-exploitation impact is severe, encompassing full data exfiltration of patient records, credential harvesting, and potential lateral movement within the hosting infrastructure. The public availability of exploit scripts exacerbates this, as it lowers the barrier for entry for automated or manual exploitation attempts against the system."
}
CVE-2026-105387: SQL Injection in Online-Appointment-Booking-System (HIGH Severity, CVSS: 7.3) | Sceawere