Skip to content
Threat Feed
high advisory

SQL Injection in Online-Appointment-Booking-System

An unauthenticated SQL injection vulnerability in the Patient Login Handler allows remote attackers to execute arbitrary SQL commands via the uname or psw parameters.

CVE search metadata

CVE search record: CVE-2026-105387. Severity: high. CVSS: 7.3. KEV: no. Product: Online-Appointment-Booking-System (<= f427b4757128ca253d33d0cc4e87bbb9c999a4d5), Online-Appointment-Booking-System (up to commit f427b4757128ca253d33d0cc4e87bbb9c999a4d5). Brief: SQL Injection in Online-Appointment-Booking-System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-sql-injection-online-appointment/

What's new

  • 1. added detection rule: Detect CVE-2026-105468 Exploitation - SQL Injection in mlogin.php Oct 5, 22:48 via nvd

A SQL injection vulnerability (CVE-2026-105387) has been identified in the Online-Appointment-Booking-System developed by girishsaraf. The vulnerability resides in the mysqli_query function within cover.php, specifically within the Patient Login Handler component. An unauthenticated remote attacker can exploit this flaw by sending specially crafted input to the uname or psw arguments.

Because the application does not properly sanitize these inputs before passing them to the database query, an attacker can manipulate the underlying SQL command. This enables unauthorized data extraction, authentication bypass, or other database-level impacts. Public exploit code for this vulnerability is currently available, increasing the risk of exploitation. As the software utilizes a rolling release model, there is no specific version number to identify a patched release, and the maintainer has not yet provided a fix for the identified vulnerability.

Impact

The successful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the database. This can lead to full compromise of the application's user database, unauthorized access to sensitive patient appointment information, and potentially complete data exfiltration.

Recommendation

Prioritized actions for security teams:

  • Identify all instances of the girishsaraf Online-Appointment-Booking-System within the environment.
  • Monitor web server access logs for anomalous characters (e.g., single quotes, comment indicators, or SQL syntax) in requests directed at cover.php.
  • Restrict access to the application via network segmentation until a patch or mitigation is verified.
  • Implement Web Application Firewall (WAF) rules to inspect and block inputs containing common SQL injection payloads targeted at the login parameters.

Immediate actions

Inventory all instances of the affected software and apply WAF filtering for CVE-2026-105387

IT Operations 48h

Threat Hunt

Search logs for unauthorized queries to cover.php

T1190 high high confidence hunt now

Data: webserver access logs

Mitigations

Block public access to the vulnerable application component

immediate IT Operations

CVE-2026-105387

Detection coverage 2

Detect CVE-2026-105387 Exploitation - SQL Injection in cover.php

high

Detects exploitation attempts against CVE-2026-105387 where SQL injection payloads are injected into the uname or psw parameters in cover.php

sigma tactics: initial_access techniques: T1190 sources: webserver

Detect CVE-2026-105468 Exploitation - SQL Injection in mlogin.php

high

Detects SQL injection attempts against the login handler of the Online-Appointment-Booking-System by identifying common SQL syntax characters in login parameters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →