Skip to content
SQL Injection Vulnerabilities in Online Appointment Booking System

SQL Injection Vulnerabilities in Online Appointment Booking System

First seen 6 Oct 2026, 01:27 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 02:26 UTC
  • •Critical SQL injection vulnerabilities allow unauthorized access to patient and admin accounts.
  • •Attackers can manipulate login requests to create valid sessions without valid credentials.
  • •Immediate evaluation and patching are necessary to mitigate risks associated with these vulnerabilities.

Two SQL injection vulnerabilities have been identified in the Online Appointment Booking System, affecting both patient and admin login endpoints. Attackers can exploit these vulnerabilities to bypass authentication and gain unauthorized access to patient, manager, or doctor sessions. The vulnerabilities arise from the direct concatenation of user credentials into SQL queries without proper escaping or prepared statements. This allows unauthenticated attackers to manipulate login requests and create sessions, enabling them to access sensitive patient information and manage appointments. The vulnerabilities are detailed in issues #5 and #6 on GitHub, published on October 6, 2026. Security professionals are urged to evaluate and patch these vulnerabilities immediately to prevent potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
Vulnerabilities disclosed
Two SQL injection vulnerabilities were reported in the Online Appointment Booking System, affecting patient and admin login endpoints.
Article 1
2026-10-06
Second vulnerability reported
A second SQL injection vulnerability was disclosed, affecting manager and doctor login endpoints, allowing unauthorized access to privileged sessions.
Article 2

More articles in this cluster (2)

Common questions

What are the affected components?
The vulnerabilities affect the patient login endpoint in cover.php, as well as the manager and doctor login endpoints in Admin/mlogin.php and Admin/dlogin.php.
How can these vulnerabilities be exploited?
Attackers can use boolean SQL injection payloads to bypass authentication and gain access to valid sessions.
What should organizations do to protect themselves?
Organizations should evaluate their systems for these vulnerabilities and apply necessary patches or mitigations immediately.