SQL Injection Vulnerability in SourceCodester Doctors Appointment System
CVE-2025-4895
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 18 May 2025
Badges
What is CVE-2025-4895?
A security vulnerability has been identified in the SourceCodester Doctors Appointment System version 1.0, specifically in the handling of the /admin/delete-session.php file. This issue arises from improper validation of the ID argument, allowing an attacker to execute SQL injection attacks remotely. Such attacks could compromise the database and lead to unauthorized data access or manipulation. The vulnerability has been publicly disclosed, emphasizing the necessity for immediate awareness and remediation to safeguard against potential exploitation.
Affected Version(s)
Doctors Appointment System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved