{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agirishsarafonline_appointment_booking_system/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:girishsaraf:online_appointment_booking_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105387"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online-Appointment-Booking-System (\u003c= f427b4757128ca253d33d0cc4e87bbb9c999a4d5)","Online-Appointment-Booking-System (up to commit f427b4757128ca253d33d0cc4e87bbb9c999a4d5)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["girishsaraf"],"content_html":"\u003cp\u003eA SQL injection vulnerability (CVE-2026-105387) has been identified in the Online-Appointment-Booking-System developed by girishsaraf. The vulnerability resides in the mysqli_query function within cover.php, specifically within the Patient Login Handler component. An unauthenticated remote attacker can exploit this flaw by sending specially crafted input to the uname or psw arguments.\u003c/p\u003e\n\u003cp\u003eBecause the application does not properly sanitize these inputs before passing them to the database query, an attacker can manipulate the underlying SQL command. This enables unauthorized data extraction, authentication bypass, or other database-level impacts. Public exploit code for this vulnerability is currently available, increasing the risk of exploitation. As the software utilizes a rolling release model, there is no specific version number to identify a patched release, and the maintainer has not yet provided a fix for the identified vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the database. This can lead to full compromise of the application's user database, unauthorized access to sensitive patient appointment information, and potentially complete data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of the girishsaraf Online-Appointment-Booking-System within the environment.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous characters (e.g., single quotes, comment indicators, or SQL syntax) in requests directed at cover.php.\u003c/li\u003e\n\u003cli\u003eRestrict access to the application via network segmentation until a patch or mitigation is verified.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect and block inputs containing common SQL injection payloads targeted at the login parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T22:48:01Z","date_published":"2026-10-05T20:48:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-sql-injection-online-appointment/","summary":"An unauthenticated SQL injection vulnerability in the Patient Login Handler allows remote attackers to execute arbitrary SQL commands via the uname or psw parameters.","title":"SQL Injection in Online-Appointment-Booking-System","url":"https://feed.craftedsignal.io/briefs/2026-10-sql-injection-online-appointment/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:girishsaraf:online_appointment_booking_system:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}