SourceCodester Dental Clinic Appointment Reservation System POST Parameter login.php sql injection
CVE-2023-1037
9.8CRITICAL
What is CVE-2023-1037?
A SQL injection vulnerability exists in the login.php file of the POST Parameter Handler component within SourceCodester's Dental Clinic Appointment Reservation System 1.0. An attacker can exploit this vulnerability by manipulating the username parameter, allowing for unauthorized access to the database. This issue can be exploited remotely, making it critical for users to apply patches or mitigations. The vulnerability has been disclosed publicly, increasing the urgency for immediate remediation.
Affected Version(s)
Dental Clinic Appointment Reservation System 1.0
