CVE-2021-27124: SQL Injection
Published Feb 18, 2021
·Updated
SQL injection in the expertise parameter in searchresult.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.
Affected Software
1 affected component
Doctor Appointment System Project Doctor Appointment System=1.0
Event History
Feb 18, 2021
CVE Published
via MITRE·03:06 AM
Data Sourced
via MITRE·03:06 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection?
The vulnerability ID is CVE-2021-27124.
2
What is the severity of CVE-2021-27124?
The severity of CVE-2021-27124 is medium.
3
How does CVE-2021-27124 in Doctor Appointment System v1.0 work?
CVE-2021-27124 allows an authenticated patient user to dump the database credentials via a SQL injection attack in the expertise parameter in search_result.php.
4
Which software version is affected by CVE-2021-27124?
Doctor Appointment System v1.0 is affected by this vulnerability.
5
Is there a fix available for CVE-2021-27124?
There is no information available about a fix for CVE-2021-27124 at the moment.