CVE-2020-29283
CRITICALOnline Doctor Appointment Booking System - SQL Injection
Title source: llmDescription
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/BigTiger2020/Online-Doctor-Appointment-Booking-System-PHP/blob/main/README.md
Product, Third Party Advisory x_refsource_misc
https://projectworlds.in/free-projects/php-projects/online-doctor-appointment-booking-system-php-and-mysql
Scores
CVSS v3
9.8
EPSS
0.0026
EPSS Percentile
49.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
online_doctor_appointment_booking_system_php_and_mysql_project/online_doctor_appointment_booking_system_php_and_mysql
1.0
Published
Dec 02, 2020
Tracked Since
Feb 18, 2026