First published: Wed Mar 24 2021(Updated: )
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Doctors Appointment System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27315 is a vulnerability in Doctor Appointment System 1.0 that allows an unauthenticated attacker to perform blind SQL injection.
CVE-2021-27315 works by allowing an attacker to inject malicious SQL queries through the 'comment' parameter in the contactus.php file.
The severity of CVE-2021-27315 is high, with a CVSS score of 7.5.
Doctor Appointment System 1.0 is affected by CVE-2021-27315.
To fix CVE-2021-27315, it is recommended to apply the latest patches or updates provided by the software vendor.