CVE-2025-4816: SourceCodester Doctor's Appointment System GET Parameter appointment.php sql injection
A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/appointment.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4816?
CVE-2025-4816 has been classified as a critical vulnerability.
What components are affected by CVE-2025-4816?
CVE-2025-4816 specifically affects the GET Parameter Handler in the /admin/appointment.php file of SourceCodester Doctor's Appointment System 1.0.
What type of vulnerability is CVE-2025-4816?
CVE-2025-4816 is a SQL injection vulnerability resulting from improper handling of the argument ID.
How can I fix CVE-2025-4816?
To fix CVE-2025-4816, input validation and parameterized queries should be implemented to prevent SQL injection.
Who is affected by CVE-2025-4816?
Users of SourceCodester Doctor's Appointment System version 1.0 are at risk of exploitation due to CVE-2025-4816.