CVE-2021-27316: SQL Injection
Published Mar 24, 2021
·Updated
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
Affected Software
1 affected component
Doctor Appointment System Project Doctor Appointment System=1.0
Event History
Mar 24, 2021
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
Description
Frequently Asked Questions
1
What is CVE-2021-27316?
CVE-2021-27316 is a vulnerability that allows an unauthenticated attacker to execute malicious SQL queries through the lastname parameter in contactus.php in doctor appointment system version 1.0.
2
How severe is CVE-2021-27316?
CVE-2021-27316 has a severity level of 7.5 (high).
3
Which software versions are affected by CVE-2021-27316?
CVE-2021-27316 affects doctor appointment system version 1.0.
4
How can an attacker exploit CVE-2021-27316?
An attacker can exploit CVE-2021-27316 by injecting malicious SQL queries through the lastname parameter in contactus.php.
5
Is there a fix for CVE-2021-27316?
To fix CVE-2021-27316, update to a patched version of doctor appointment system that addresses the vulnerability.