SQL Injection Vulnerability in girishsaraf Online-Appointment-Booking-System
CVE-2026-105471
Key Information:
- Vendor
Girishsaraf
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-105471?
A security vulnerability has been identified in the girishsaraf Online-Appointment-Booking-System, particularly affecting the signup.php file within its Registration Handler component. This flaw allows attackers to manipulate the 'fname' parameter, leading to SQL injection vulnerabilities. As a result, unauthorized users could execute arbitrary SQL queries from a remote location. The exploit has been publicly disclosed, highlighting the urgency for system administrators to secure their applications against potential intrusions. Despite being notified early about the issue by users via an issue report, the development team has yet to respond. It is crucial for all users to take immediate action to protect their systems.
Affected Version(s)
Online-Appointment-Booking-System f427b4757128ca253d33d0cc4e87bbb9c999a4d5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
