Sceawere

Vulnerability Detail

CVE-2026-105468UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Online-Appointment-Booking-System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
1h ago
Vendor
girishsaraf
Product
Online-Appointment-Booking-System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T22:16:56.683Z",
  "pubdate": "2026-10-05T22:16:56.683Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the Login Handler component of the girishsaraf Online-Appointment-Booking-System, specifically within the Admin/mlogin.php file.\nThe vulnerability arises from improper neutralization of special elements used in SQL commands within the 'uname' and 'pass' input parameters.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries, potentially leading to unauthorized access, data exfiltration, or modification of the underlying database.\nGiven that the vulnerability is publicly disclosed and the project maintainers have remained unresponsive, the system faces an elevated risk of exploitation by malicious actors.\nSuccessful exploitation allows attackers to bypass authentication mechanisms entirely, gaining administrative access to the system without legitimate credentials.",
  "technicalDetails": "The vulnerability resides in the mysqli_query function within Admin/mlogin.php. The root cause is the direct concatenation of user-supplied input (the 'uname' and 'pass' parameters) into a SQL query string without the use of prepared statements or parameterized queries.\nIn the affected version (up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5), the application takes the input provided in the login POST request and immediately incorporates it into an authentication query intended to verify credentials against the database. Because the input is not sanitized or bound to the query, an attacker can supply specially crafted SQL syntax characters, such as single quotes ('), comment operators (-- or #), or logical tautologies (e.g., 'OR 1=1').\nThe attack flow begins with the attacker targeting the public-facing login endpoint. Instead of providing standard credentials, the attacker injects malicious SQL tokens into the 'uname' or 'pass' fields. When the server processes this input via mysqli_query, the database engine interprets the injected content as part of the command structure rather than literal data. For instance, an injection payload like 'admin'-- can be used to terminate the query prematurely, effectively bypassing the password check for the administrative account.\nThis is a remote, unauthenticated attack vector. No prior access to the system is required to initiate the request. The network exposure is absolute, as the login portal is typically accessible over HTTP/HTTPS from any client reachable by the web server.\nPost-exploitation impact is severe. Beyond simple authentication bypass, an attacker can leverage this vulnerability to execute UNION-based attacks to extract sensitive information from other tables within the database schema, perform blind SQL injection to enumerate data character-by-character, or, depending on the database configuration and permissions, potentially escalate privileges or modify existing records.\nThe absence of input validation and the reliance on insecure query construction techniques characterize this as a classic SQL Injection vulnerability (CWE-89). The failure to implement parameterized queries represents a critical security oversight in the application's authentication flow."
}
CVE-2026-105468: SQL Injection in Online-Appointment-Booking-System (HIGH Severity, CVSS: 7.3) | Sceawere