CVE-2025-3180: projectworlds Online Doctor Appointment Booking System deleteschedule.php sql injection
A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3180?
CVE-2025-3180 is classified as a critical vulnerability that allows SQL injection through the file /doctor/deleteschedule.php.
How do I fix CVE-2025-3180?
To fix CVE-2025-3180, ensure proper input validation and use prepared statements to mitigate SQL injection risks.
What components are affected by CVE-2025-3180?
CVE-2025-3180 affects the Online Doctor Appointment Booking System version 1.0 developed by projectworlds.
Can CVE-2025-3180 lead to data loss?
Yes, exploiting CVE-2025-3180 can potentially lead to unauthorized access and manipulation of the database, resulting in data loss.
Is CVE-2025-3180 easy to exploit?
CVE-2025-3180 is considered easy to exploit due to the SQL injection vulnerability in the application.