Junglewise Threat Intelligence

CVE-2026-85403: code-projects Doctor Appointment System SQL injection in contactus.php

CVE-2026-85403 · Severity: high · CVSS 7.3 · Published 2026-09-04

Vendors: Code-Projects.

Executive brief

Doctor Appointment System is a PHP-based web application for managing doctor appointments. A SQL injection vulnerability in the contact form allows attackers to inject malicious database commands through the firstname parameter without authentication, potentially exposing patient records, modifying appointment data, or taking control of the underlying database.

Technical details

A SQL injection vulnerability exists in the /contactus.php file where the 'firstname' POST parameter is directly concatenated into SQL queries without proper input sanitization or parameterized statements. An unauthenticated remote attacker can exploit this via boolean-based blind, error-based, or time-based blind SQL injection techniques to extract sensitive database contents, modify data, or execute arbitrary database operations. The vulnerability is network-reachable via HTTP POST and requires no authentication or user interaction. Prepared statements and input validation are recommended as fixes.

Affected products

  • code-projects Doctor Appointment System 1.0

Timeline

  • 2026-07-18: disclosed: Vulnerability disclosed on GitHub issue #6
  • 2026-09-04: advisory: CVE-2026-85403 published on NVD

References