Executive brief
An online clinic appointment scheduling system contains a SQL injection vulnerability in its public doctor directory search feature. An attacker can manipulate the search parameter to extract sensitive data from the database, including administrator login credentials and patient/doctor personal information, without requiring authentication. This could lead to account takeover and unauthorized access to confidential patient records.
Technical details
The vulnerability is a classic SQL injection flaw in listdoctor.php where user-supplied input from the POST parameter searchtext is directly concatenated into a SQL query without sanitization or parameterized statements (lines 7–11: SELECT * FROM doc_registration where doc_name='$ami' or doc_dept='$ami'...). An unauthenticated attacker can inject UNION SELECT statements to extract arbitrary columns from other tables, such as admin_registration, exposing administrator usernames, passwords, and email addresses. The attack requires network access to the affected web application and no authentication; the injected payload is executed server-side and results are reflected in the HTML response. The project uses a rolling release model with no formal version tracking; the vulnerable code was present up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578 on 2026-08-05 when the issue was first reported, but the maintainer has not yet responded or released a patch.
Affected products
- subhajitkhan online-clinic-management-system up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578
Timeline
- 2026-08-05: disclosed: Issue #2 filed on GitHub with public reproduction steps and proof of concept
- 2026-09-14: advisory: CVE-2026-90701 published; NVD entry created