Description
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to unauthorized data exposure
Action: Assess Impact
AI Analysis

Impact

A flaw in the doctorlogin.php component of the online clinic management system allows remote manipulation of the doc_mail and doc_pswd parameters to inject arbitrary SQL statements. This vulnerability, classified as CWE-74 and CWE-89, can lead to compromise of sensitive data stored in the underlying database and may allow attackers to alter or delete records. The impact is primarily the confidentiality and integrity of patient and administrative information.

Affected Systems

The affected product is subhajitkhan:online-clinic-management-system, specifically up to the commit e9ee77a8827a1446220fa07ee693dc4d9a29a578. The system follows a rolling release model, so no explicit version numbers are available for the vulnerable state.

Risk and Exploitability

The CVSS severity score of 6.9 indicates a medium to high risk. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV. Publication of an exploit and the ability to trigger the flaw remotely suggest a realistic threat. Because the attack vector is remote via standard web requests, any exposed instance of the application is susceptible until mitigated.

Generated by OpenCVE AI on September 15, 2026 at 07:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the application to a version released after the vulnerable commit or apply an official vendor patch as soon as it becomes available.
  • If no patch is available, immediately restrict access to doctorlogin.php, for example by blocking remote IPs or requiring additional authentication before the script is executed.
  • Modify the vulnerable code to use prepared statements or parameterized queries, ensuring that user-supplied values for doc_mail and doc_pswd are properly sanitized before inclusion in SQL commands.

Generated by OpenCVE AI on September 15, 2026 at 07:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title subhajitkhan online-clinic-management-system doctorlogin.php sql injection
First Time appeared Subhajitkhan
Subhajitkhan online-clinic-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:subhajitkhan:online-clinic-management-system:*:*:*:*:*:*:*:*
Vendors & Products Subhajitkhan
Subhajitkhan online-clinic-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Subhajitkhan Online-clinic-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T15:45:24.835Z

Reserved: 2026-09-13T15:35:47.477Z

Link: CVE-2026-90805

cve-icon Vulnrichment

Updated: 2026-09-15T15:45:21.349Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:27.767

Modified: 2026-09-15T16:17:41.713

Link: CVE-2026-90805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:00:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')