SQL Injection in Online-Appointment-Booking-System
An unauthenticated SQL injection vulnerability in the Patient Login Handler allows remote attackers to execute arbitrary SQL commands via the uname or psw parameters.
CVE search metadata
CVE search record: CVE-2026-105387. Severity: high. CVSS: 7.3. KEV: no. Product: Online-Appointment-Booking-System (<= f427b4757128ca253d33d0cc4e87bbb9c999a4d5), Online-Appointment-Booking-System (up to commit f427b4757128ca253d33d0cc4e87bbb9c999a4d5). Brief: SQL Injection in Online-Appointment-Booking-System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-sql-injection-online-appointment/
What's new
- 1. added detection rule: Detect CVE-2026-105468 Exploitation - SQL Injection in mlogin.php Oct 5, 22:48 via nvd
A SQL injection vulnerability (CVE-2026-105387) has been identified in the Online-Appointment-Booking-System developed by girishsaraf. The vulnerability resides in the mysqli_query function within cover.php, specifically within the Patient Login Handler component. An unauthenticated remote attacker can exploit this flaw by sending specially crafted input to the uname or psw arguments.
Because the application does not properly sanitize these inputs before passing them to the database query, an attacker can manipulate the underlying SQL command. This enables unauthorized data extraction, authentication bypass, or other database-level impacts. Public exploit code for this vulnerability is currently available, increasing the risk of exploitation. As the software utilizes a rolling release model, there is no specific version number to identify a patched release, and the maintainer has not yet provided a fix for the identified vulnerability.
Impact
The successful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the database. This can lead to full compromise of the application's user database, unauthorized access to sensitive patient appointment information, and potentially complete data exfiltration.
Recommendation
Prioritized actions for security teams:
- Identify all instances of the girishsaraf Online-Appointment-Booking-System within the environment.
- Monitor web server access logs for anomalous characters (e.g., single quotes, comment indicators, or SQL syntax) in requests directed at cover.php.
- Restrict access to the application via network segmentation until a patch or mitigation is verified.
- Implement Web Application Firewall (WAF) rules to inspect and block inputs containing common SQL injection payloads targeted at the login parameters.
Immediate actions
Inventory all instances of the affected software and apply WAF filtering for CVE-2026-105387
Threat Hunt
Search logs for unauthorized queries to cover.php
Data: webserver access logs
Mitigations
Block public access to the vulnerable application component
CVE-2026-105387
Detection coverage 2
Detect CVE-2026-105387 Exploitation - SQL Injection in cover.php
highDetects exploitation attempts against CVE-2026-105387 where SQL injection payloads are injected into the uname or psw parameters in cover.php
Detect CVE-2026-105468 Exploitation - SQL Injection in mlogin.php
highDetects SQL injection attempts against the login handler of the Online-Appointment-Booking-System by identifying common SQL syntax characters in login parameters.
Detection queries are available on the platform. Get full rules →