CVE-2021-27319

HIGH NUCLEI

Doctor Appointment System 1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-27319 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.

Nuclei Templates (1)

Doctor Appointment System 1.0 - SQL Injection
HIGHVERIFIEDby theamanrawat

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0783
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
doctor_appointment_system_project/doctor_appointment_system 1.0
Published Mar 24, 2021
Tracked Since Feb 18, 2026