CVE-2021-27320

HIGH NUCLEI

Doctor Appointment System 1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-27320 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

Nuclei Templates (1)

Doctor Appointment System 1.0 - SQL Injection
HIGHVERIFIEDby theamanrawat

References (2)

Core 2
Core References
Product, Third Party Advisory x_refsource_misc
https://www.sourcecodester.com/php/14182/doctor-appointment-system.html

Scores

CVSS v3 7.5
EPSS 0.0930
EPSS Percentile 94.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
doctor_appointment_system_project/doctor_appointment_system 1.0
Published Mar 24, 2021
Tracked Since Feb 18, 2026