CVE-2026-19384: SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=setappointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19384?
The severity of CVE-2026-19384 is rated as high with a score of 7.3.
What are the potential impacts of CVE-2026-19384?
CVE-2026-19384 allows for SQL injection, which can lead to unauthorized access to database information.
How can I fix CVE-2026-19384?
To fix CVE-2026-19384, ensure proper input validation and parameterized queries are implemented in the affected file /admin/ajax.php.
Is CVE-2026-19384 exploitable remotely?
Yes, CVE-2026-19384 can be exploited remotely.
What component is affected by CVE-2026-19384?
CVE-2026-19384 affects the /admin/ajax.php file in the SourceCodester Simple Doctors Appointment System 1.0.