Junglewise Threat Intelligence

CVE-2026-90701: subhajitkhan online-clinic-management-system SQL injection in listdoctor.php

CVE-2026-90701 · Severity: high · CVSS 7.3 · Published 2026-09-14

Technologies: Subhajitkhan Online Clinic Management System.

Executive brief

An online clinic appointment scheduling system contains a SQL injection vulnerability in its public doctor directory search feature. An attacker can manipulate the search parameter to extract sensitive data from the database, including administrator login credentials and patient/doctor personal information, without requiring authentication. This could lead to account takeover and unauthorized access to confidential patient records.

Technical details

The vulnerability is a classic SQL injection flaw in listdoctor.php where user-supplied input from the POST parameter searchtext is directly concatenated into a SQL query without sanitization or parameterized statements (lines 7–11: SELECT * FROM doc_registration where doc_name='$ami' or doc_dept='$ami'...). An unauthenticated attacker can inject UNION SELECT statements to extract arbitrary columns from other tables, such as admin_registration, exposing administrator usernames, passwords, and email addresses. The attack requires network access to the affected web application and no authentication; the injected payload is executed server-side and results are reflected in the HTML response. The project uses a rolling release model with no formal version tracking; the vulnerable code was present up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578 on 2026-08-05 when the issue was first reported, but the maintainer has not yet responded or released a patch.

Affected products

  • subhajitkhan online-clinic-management-system up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578

Timeline

  • 2026-08-05: disclosed: Issue #2 filed on GitHub with public reproduction steps and proof of concept
  • 2026-09-14: advisory: CVE-2026-90701 published; NVD entry created

References