SourceCodester Patient Appointment Scheduler System version 1.0 contains a SQL Injection vulnerability in the /scheduler/admin/user/manage_user.php file that could allow an attacker to manipulate database queries. The vulnerability has a CVSS score of 2.7 (Low severity) and requires network access with high-level administrative privileges to exploit. The attack vector is network-based with low complexity, and the potential impact is limited to low-level confidentiality compromise with no integrity or availability risks. There is no evidence of active exploitation in the wild, the vulnerability is not tracked on the Known Exploited Vulnerabilities (KEV) list, and it maintains an inactive status on threat intelligence hot lists, indicating minimal community attention and current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.