PT-2025-48713 · Unknown · Edoc-Doctor-Appointment-System

CVE-2025-65358

·

Published

2025-12-02

·

Updated

2025-12-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Edoc-doctor-appointment-system version 1.0.1
Description The Edoc-doctor-appointment-system software contains a SQL injection issue. This issue is located in the /admin/appointment.php file and affects the docid parameter. Exploitation of this issue could allow an attacker to potentially compromise the database.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /admin/appointment.php file or sanitize the docid parameter to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65358

Affected Products

Edoc-Doctor-Appointment-System