Impact
A flaw in the /contactus.php page of the Code-Projects Doctor Appointment System allows attackers to manipulate the firstname field and inject arbitrary SQL code. The vulnerability enables unintended database queries, exposing sensitive user data or facilitating further system compromise. The description indicates that remote exploitation is possible, and an exploit has already been published, suggesting that the flaw is actionable from outside the local network.
Affected Systems
The impacted product is Code-Projects Doctor Appointment System, version 1.0. No additional vendors, products, or revision details are listed in the available data.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate to high severity. Because the EPSS score is not available and the vulnerability is not yet in CISA’s KEV catalog, the overall risk is governed by the presence of a publicly released exploit and the possibility of remote attack. These conditions raise the likelihood that an attacker could exploit the flaw and compromise the database state.
OpenCVE Enrichment