ZeroHour

CVE-2021-27314

PoC
CVSS 3.1
9.8 critical
EPSS
12%p96
Published
()
Modified
Description

SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

Vendors
doctor appointment system project
Products
doctor appointment system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.