Vendor
An unauthenticated SQL injection vulnerability (CVE-2026-90701) in the online-clinic-management-system allows remote attackers to manipulate database queries via the listdoctor.php searchtext parameter.