Impact
An SQL injection flaw in the delete_appointment action of SourceCodester Simple Doctors Appointment System 1.0 allows remote attackers to manipulate the ID parameter in /admin/ajax.php. The issue can lead to extraction of sensitive appointment data, alteration of records, or potentially broader database compromise, undermining confidentiality and integrity. The vulnerability is classified under CWE‑74 and CWE‑89.
Affected Systems
The affected product is SourceCodester Simple Doctors Appointment System version 1.0, accessed via the admin/ajax.php endpoint. No additional version details are available beyond the primary release.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that while public exploits exist, the probability of widespread exploitation remains uncertain. Attackers can launch the exploit remotely against systems hosting the aforementioned application, provided they can reach the administrative interface.
OpenCVE Enrichment