CVE-2025-7540: code-projects Online Appointment Booking System getclinic.php sql injection
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7540?
CVE-2025-7540 is classified as a critical vulnerability.
How do I fix CVE-2025-7540?
To fix CVE-2025-7540, input validation should be implemented to sanitize and parameterize SQL queries effectively.
What type of vulnerability is CVE-2025-7540?
CVE-2025-7540 is an SQL injection vulnerability.
Which application is affected by CVE-2025-7540?
CVE-2025-7540 affects the Online Appointment Booking System 1.0 by code-projects.
What is the exploit vector for CVE-2025-7540?
The exploit vector for CVE-2025-7540 involves manipulating the 'townid' argument in the /getclinic.php file.