CVE-2025-3179: projectworlds Online Doctor Appointment Booking System deletepatient.php sql injection
A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3179?
CVE-2025-3179 is classified as a critical vulnerability due to its potential for SQL injection attacks.
What systems are affected by CVE-2025-3179?
CVE-2025-3179 affects the Online Doctor Appointment Booking System version 1.0 by projectworlds.
How do I fix CVE-2025-3179?
To fix CVE-2025-3179, sanitize and validate all inputs in the /doctor/deletepatient.php file to prevent SQL injection.
Can CVE-2025-3179 lead to data breaches?
Yes, CVE-2025-3179 can lead to data breaches by allowing attackers to manipulate the database through SQL injection.
Is there a patch available for CVE-2025-3179?
As of now, there is no specific patch announced for CVE-2025-3179, so immediate manual fixes are recommended.