First published: Thu Apr 03 2025(Updated: )
A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Doctor Appointment System | =1.0 | |
Projectworlds Online Doctor Appointment Booking System Php And Mysql |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3179 is classified as a critical vulnerability due to its potential for SQL injection attacks.
CVE-2025-3179 affects the Online Doctor Appointment Booking System version 1.0 by projectworlds.
To fix CVE-2025-3179, sanitize and validate all inputs in the /doctor/deletepatient.php file to prevent SQL injection.
Yes, CVE-2025-3179 can lead to data breaches by allowing attackers to manipulate the database through SQL injection.
As of now, there is no specific patch announced for CVE-2025-3179, so immediate manual fixes are recommended.