SQL Injection Vulnerability in girishsaraf Online-Appointment-Booking-System AJAX Endpoint
CVE-2026-105469
Key Information:
- Vendor
Girishsaraf
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-105469?
A vulnerability exists in the girishsaraf Online-Appointment-Booking-System that affects the AJAX Endpoint component. The flaw is found in the get_town.php file, where improper handling of parameters like countryid, townid, cid, didval, and cidval can lead to SQL injection attacks. Attackers may exploit this vulnerability remotely, allowing malicious SQL commands to be executed, potentially compromising the integrity of the database. Despite being reported to the developers, no resolution has been provided, leaving users at risk.
Affected Version(s)
Online-Appointment-Booking-System f427b4757128ca253d33d0cc4e87bbb9c999a4d5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
