CVE-2021-27124 is a SQL injection vulnerability in the Doctor Appointment System v1.0, specifically within the 'expertise' parameter of search_result.php, allowing an authenticated patient user to extract database credentials. With a CVSS score of 6.5 (Medium), this vulnerability can be exploited remotely with low attack complexity and requires only low privileges, leading to high confidentiality impact. While not present in CISA's KEV catalog, Nuclei templates exist for this vulnerability, indicating readily available exploit code, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:doctor_appointment_system_project:doctor_appointment_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.