SQL Injection Vulnerability in PHPGurukul Doctor Appointment Management System
CVE-2025-2383
9.8CRITICAL
Key Information:
- Vendor
- PHPGurukul
- Vendor
- CVE Published:
- 17 March 2025
Summary
A SQL injection vulnerability exists in PHPGurukul's Doctor Appointment Management System 1.0 due to improper handling of the 'searchdata' parameter in the /doctor/search.php file. This weakness allows an attacker to manipulate SQL queries, potentially leading to unauthorized data access or manipulation. Remote exploitation of this flaw may result in the extraction of sensitive information and can pose significant risks to the integrity and confidentiality of the system. As the exploit has been publicly disclosed, users are advised to take immediate action to secure their installations.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published