Executive brief
Doctor Appointment System is a web application used for managing patient and doctor interactions. A flaw in the patient login page allows attackers to inject malicious SQL commands via the email field, potentially exposing sensitive patient data, appointment records, or gaining unauthorized access to the system without valid credentials.
Technical details
The vulnerability is a time-based blind SQL injection in the /patient_login.php file, specifically in the email parameter handling. The application fails to properly sanitize or parameterize user input before incorporating it into SQL queries, allowing an attacker to craft malicious email values that alter query logic. The attack is remotely exploitable and requires no authentication; an attacker can interact with the publicly accessible login form to inject SQL commands. Successful exploitation enables database enumeration, data extraction, authentication bypass, or potential remote code execution depending on database permissions. Public exploits are available, indicating active community interest in this vulnerability.
Affected products
- code-projects Doctor Appointment System 1.0
Timeline
- 2026-09-03: disclosed
- other: Exploit publicly available via GitHub