9.8
CVSSv3

CVE-2023-39852

Published: 15/08/2023 Updated: 04/06/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

Doctormms v1.0 exists to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that this originates from $_SESSION["userid"]=$_POST["userid"] at line 68 in doctors\doctorlogin.php, where userid under POST is not a session variable controlled by the server.

Vulnerable Product Search on Vulmon Subscribe to Product

doctor appointment system project doctor appointment system 1.0