Executive brief
Online-Clinic-Management-System is a web-based appointment scheduling platform that allows doctors, patients, and administrators to manage healthcare services. An attacker who knows a doctor's email address can bypass authentication in the doctor login page by injecting SQL code into email or password fields, gaining unauthorized access to doctor accounts and patient appointment data without needing a valid password.
Technical details
The vulnerability is a classic SQL injection flaw in the doctor login module (doctorlogin.php). The vulnerable code directly concatenates unsanitized POST parameters (doc_mail and doc_pswd) into a SQL SELECT query without using prepared statements or input validation. An unauthenticated attacker can craft a malicious email address (e.g., "doctor@example.test' AND '1'='1' -- ") that bypasses the password check and returns a valid doctor record, establishing a session. The injected payload persists in the session and is used again in doctorhome.php, allowing full access to the doctor portal without authentication. No authentication or special privileges are required to exploit this vulnerability; a remote attacker only needs to know a doctor's email address. The project uses a rolling release model and has not yet responded to the early disclosure report.
Affected products
- subhajitkhan Online-Clinic-Management-System up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578
Timeline
- 2026-08-10: disclosed: Issue reported on GitHub
- 2026-09-14: advisory: Published on NVD as CVE-2026-90805