SQL Injection Vulnerability in girishsaraf Online-Appointment-Booking-System
CVE-2026-105471

6.9MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-105471?

A security vulnerability has been identified in the girishsaraf Online-Appointment-Booking-System, particularly affecting the signup.php file within its Registration Handler component. This flaw allows attackers to manipulate the 'fname' parameter, leading to SQL injection vulnerabilities. As a result, unauthorized users could execute arbitrary SQL queries from a remote location. The exploit has been publicly disclosed, highlighting the urgency for system administrators to secure their applications against potential intrusions. Despite being notified early about the issue by users via an issue report, the development team has yet to respond. It is crucial for all users to take immediate action to protect their systems.

Affected Version(s)

Online-Appointment-Booking-System f427b4757128ca253d33d0cc4e87bbb9c999a4d5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

jiqinwang (VulDB User)
VulDB CNA Team
.