CVE-2021-27315
HIGH NUCLEIDoctor Appointment System 1.0 - SQL Injection
Title source: llmDescription
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
Nuclei Templates (1)
Doctor Appointment System 1.0 - SQL Injection
HIGHVERIFIEDby theamanrawat
Scores
CVSS v3
7.5
EPSS
0.7138
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (1)
doctor_appointment_system_project/doctor_appointment_system
1.0
Published
Mar 24, 2021
Tracked Since
Feb 18, 2026