CVE-2025-13122: SourceCodester Patients Waiting Area Queue Management System api_patient_checkin.php getPatientAppointment sql injection
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/apipatientcheckin.php. Performing manipulation of the argument appointmentID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13122?
CVE-2025-13122 is assessed as a high severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-13122?
To fix CVE-2025-13122, validate and sanitize the input of the appointmentID parameter to prevent SQL injection.
What systems are affected by CVE-2025-13122?
CVE-2025-13122 affects the SourceCodester Patients Waiting Area Queue Management System version 1.0.
What type of vulnerability is CVE-2025-13122?
CVE-2025-13122 is classified as an SQL injection vulnerability.
What can attackers do by exploiting CVE-2025-13122?
By exploiting CVE-2025-13122, attackers can manipulate database queries, potentially leading to unauthorized data access.