CVE-2026-3980 describes a critical SQL injection vulnerability in itsourcecode Online Doctor Appointment System 1.0, specifically within the /admin/patient_action.php file when manipulating the patient_id argument. This flaw carries a CVSSv3.1 score of 9.8 (Critical), indicating a severe risk. It allows unauthenticated remote attackers with low attack complexity to achieve complete compromise of confidentiality, integrity, and availability. Although not currently on CISA's KEV list or widely discussed, public exploit details have been disclosed. This makes affected systems vulnerable to potential future attacks despite minimal community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:unguardable:online_doctor_appointment_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.