vendor:
Online Appointment Booking System
by:
mohammad zaheri
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online Appointment Booking System
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2019
Online Appointment SQL Injection
This exploit allows an attacker to inject SQL queries into the 'signup.php' page of the Online Appointment Booking System, leading to unauthorized access to the database.
Mitigation:
To mitigate this vulnerability, the developer should use parameterized queries or prepared statements to sanitize user input.