SQL Injection Vulnerability in SourceCodester Dental Clinic Appointment Reservation System
CVE-2025-13267
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 17 November 2025
Badges
What is CVE-2025-13267?
A SQL injection vulnerability was identified within the SourceCodester Dental Clinic Appointment Reservation System 1.0, specifically affecting the '/success.php' file. An attacker can exploit this flaw by manipulating the 'username/password' parameters, allowing unauthorized access to the database. This vulnerability can be exploited remotely, making it crucial for users to assess their system's security and apply the necessary updates or mitigations to prevent potential attacks.
Affected Version(s)
Dental Clinic Appointment Reservation System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
