NA

CVE-2022-36202

Published: 31/08/2022 Updated: 14/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

doctor\\'s appointment system project doctor\\'s appointment system 1.0

Github Repositories

a list of my CVEs

a list of my CVEs CVE-2022-36201 A Blind SQLi vulnerability was found in Doctor's Appointment System version 10 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2022-36201 CVE-2022-36202 Doctor's Appointment System version 10 was affected by Improper Access Control vulnerability leads to privilege escalation cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2