CVE-2026-85403: code-projects Doctor Appointment System contactus.php sql injection
A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What must an attacker be able to do to exploit this issue?
An attacker can exploit the issue remotely by manipulating the firstname argument processed by /contactus.php. No authentication or user interaction is indicated by the supplied severity vector.
How likely is exploitation in practice?
The attack complexity is rated low, and a public exploit has been published. Systems with the affected contactus.php processing exposed remotely should be treated as at risk.
What is the potential impact?
The supplied vector indicates low impacts to confidentiality, integrity, and availability. The vulnerability is classified as SQL injection.