CVE-2026-37598: SQL Injection
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=updatesettings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-37598?
CVE-2026-37598 has a severity rating that indicates a critical risk due to its potential for arbitrary code execution.
How do I fix CVE-2026-37598?
To fix CVE-2026-37598, update the SourceCodester Patient Appointment Scheduler System to the latest version that addresses this vulnerability.
What is CVE-2026-37598?
CVE-2026-37598 is a vulnerability in SourceCodester Patient Appointment Scheduler System v1.0 that allows for arbitrary code execution via a flaw in the update settings functionality.
Who is affected by CVE-2026-37598?
The vulnerability CVE-2026-37598 affects users of SourceCodester Patient Appointment Scheduler System version 1.0.
What is the attack vector for CVE-2026-37598?
The attack vector for CVE-2026-37598 is through a malicious request sent to /scheduler/classes/SystemSettings.php?f=update_settings.