Subhajitkhan · Online Clinic Management System · CVE-2026-90805
**Name of the Vulnerable Software and Affected Versions**
subhajitkhan online-clinic-management-system versions up to e9ee77a8827a1446220fa07ee693dc4d9a29a578
**Description**
A remote SQL injection flaw exists in the `doctorlogin.php` file. This issue occurs when the `doc mail` and `doc pswd` arguments are manipulated, allowing an attacker to execute unauthorized database queries.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.