CVE-2021-27320

HIGH NUCLEI

Doctor Appointment System 1.0 - SQL Injection

Title source: llm

Description

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

Nuclei Templates (1)

Doctor Appointment System 1.0 - SQL Injection
HIGHVERIFIEDby theamanrawat

Scores

CVSS v3 7.5
EPSS 0.7625
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
doctor_appointment_system_project/doctor_appointment_system 1.0
Published Mar 24, 2021
Tracked Since Feb 18, 2026