Description
A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to unauthorized data access
Action: Monitor
AI Analysis

Impact

The flaw exists in an undefined function within listdoctor.php. By supplying a crafted searchtext parameter, a remote attacker can inject arbitrary SQL into the backend query. The vulnerability is classified as CWE‑74 and CWE‑89.

Affected Systems

The affected product is the online‑clinic‑management‑system developed by subhajitkhan. The repository uses a rolling‑release model and does not publish immutable version numbers. Any build that contains the commit hash e9ee77a8827a1446220fa07ee693dc4d9a29a578 or prior may be affected, and no fixed release has been issued yet. The developer has acknowledged the issue but has not released a fix.

Risk and Exploitability

The CVSS score of 6.9 marks the vulnerability as medium severity. The EPSS score is listed as < 1 %, indicating a very low probability of active exploitation, and the vulnerability is not included in the CISA KEV catalog. The exploit can be launched remotely by submitting a crafted searchtext value to /listdoctor.php. The description does not mention authentication requirements or other prerequisites.

Generated by OpenCVE AI on September 15, 2026 at 15:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Modify listdoctor.php to use parameterized queries or prepared statements for any SQL that incorporates the searchtext input, and validate the input to allow only expected characters.
  • Restrict the database user account used by the application to the minimum privileges required for normal operation, limiting the potential damage from any successful injection.
  • Deploy a Web Application Firewall or similar rule set to detect and block suspicious SQL payloads on the /listdoctor.php endpoint until a code fix is applied.

Generated by OpenCVE AI on September 15, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Title subhajitkhan online-clinic-management-system listdoctor.php sql injection
First Time appeared Subhajitkhan
Subhajitkhan online-clinic-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:subhajitkhan:online-clinic-management-system:*:*:*:*:*:*:*:*
Vendors & Products Subhajitkhan
Subhajitkhan online-clinic-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Subhajitkhan Online-clinic-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T14:34:19.801Z

Reserved: 2026-09-13T05:28:42.706Z

Link: CVE-2026-90701

cve-icon Vulnrichment

Updated: 2026-09-14T14:34:14.135Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T10:17:05.233

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')