CVE-2025-3186: projectworlds Online Doctor Appointment Booking System invoice.php sql injection
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient/invoice.php. The manipulation of the argument appid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3186?
CVE-2025-3186 has been declared as critical due to its potential impact on the security of the application.
What component is affected by CVE-2025-3186?
CVE-2025-3186 affects the functionality of the file /patient/invoice.php in the Online Doctor Appointment Booking System.
What type of vulnerability is CVE-2025-3186?
CVE-2025-3186 is classified as an SQL injection vulnerability.
How do I fix CVE-2025-3186?
To fix CVE-2025-3186, you should implement input validation and parameterized queries to mitigate SQL injection risks.
What can attackers do with CVE-2025-3186?
Attackers exploiting CVE-2025-3186 may manipulate the appid argument to gain unauthorized access or compromise the database.