CVE-2021-27314 - SQL Injection vulnerability in Doctor Appointment System v. 1.0


The Doctor Appointment System is a web application designed to facilitate the scheduling of appointments between patients and healthcare providers. It is used by clinics and hospitals to manage patient appointments efficiently, allowing users to book, cancel, or reschedule their appointments online. This system aims to streamline the appointment booking process, reduce administrative workload, and improve the overall patient care experience. It is particularly beneficial for healthcare facilities looking to digitize their appointment scheduling and patient management processes. By providing a centralized platform, it enhances the accessibility and convenience for both patients and healthcare providers.

The vulnerability is present in the admin.php file of the Doctor Appointment System version 1.0. It arises due to improper sanitization of user inputs in the username field on the login page. Attackers can exploit this by inserting malicious SQL code into the username field, which is then executed by the database server. This can lead to unauthorized access, data leakage, and potentially, complete system compromise. The lack of input validation and prepared statements makes it susceptible to SQL injection attacks, highlighting a critical security oversight in the application's development.

Successful exploitation of this vulnerability could have severe consequences, including but not limited to unauthorized access to patient records, alteration or deletion of critical data, disruption of healthcare services, and potential breaches of patient confidentiality. It could lead to a loss of trust in the healthcare provider, legal repercussions, and significant financial losses associated with remediation efforts and potential penalties for non-compliance with data protection regulations.

