SQL Injection Vulnerability in SourceCodester Patient Appointment Scheduler System
CVE-2026-37600
2.7LOW
Key Information:
- Vendor
SourceCodester
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-37600?
The SourceCodester Patient Appointment Scheduler System version 1.0 is compromised by a SQL Injection vulnerability found in the /scheduler/admin/appointments/view_details.php file. This issue allows unauthorized users to manipulate database queries through crafted input, potentially leading to data exposure or unauthorized access. It is crucial for developers and administrators using this system to apply security measures to prevent exploitation.
