Sceawere
Vulnerability Detail
CVE-2026-105387UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online-Appointment-Booking-System
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- girishsaraf
- Product
- Online-Appointment-Booking-System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T19:17:16.910Z",
"pubdate": "2026-10-05T19:17:16.910Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the Patient Login Handler of the girishsaraf Online-Appointment-Booking-System, affecting versions up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5.\nThe vulnerability stems from improper neutralization of special elements used in an SQL command within the cover.php file. By manipulating the 'uname' or 'psw' arguments, an unauthenticated remote attacker can inject malicious SQL queries.\nThis flaw allows unauthorized access to the backend database, potentially leading to the exposure of sensitive patient information, authentication bypass, or complete database compromise.\nAs the project utilizes a rolling release model and lacks an official vendor patch, the system remains in a vulnerable state. Given that exploit code is publicly available, the risk of exploitation by malicious actors is high. No specific authentication or complex privileges are required to initiate the attack, making it a significant threat to system integrity and data confidentiality.",
"technicalDetails": "The root cause of the vulnerability is the usage of unsanitized user-supplied input within the mysqli_query function located in cover.php. The application fails to employ prepared statements or parameterized queries when processing the 'uname' (username) and 'psw' (password) parameters during the authentication handshake.\nThe exploitation flow begins with the attacker sending a crafted HTTP POST request to the affected login endpoint. Instead of providing standard credentials, the attacker injects SQL metacharacters (such as single quotes, comment delimiters, or UNION operators) into the 'uname' or 'psw' fields. Because the input is concatenated directly into the backend SQL string, the database management system interprets the attacker's input as executable code rather than literal data.\nBy manipulating the query structure, an attacker can effectively terminate the intended authentication statement and append arbitrary SQL commands. This allows the attacker to bypass the intended authentication mechanism, execute unauthorized SELECT queries to dump database contents, or modify/delete existing data. In environments where the database user possesses sufficient permissions, it may be possible to escalate privileges or interact with the underlying host file system.\nThe vulnerability is remotely exploitable over the network without requiring pre-existing authentication. The application's design, specifically the handler within cover.php, performs direct string concatenation, creating an injection vector. The lack of input validation or output encoding on these parameters ensures that any crafted payload is executed with the privileges of the database service account.\nPost-exploitation impact is severe, encompassing full data exfiltration of patient records, credential harvesting, and potential lateral movement within the hosting infrastructure. The public availability of exploit scripts exacerbates this, as it lowers the barrier for entry for automated or manual exploitation attempts against the system."
}