peter bassill · operator
$ cve CVE-2021-27314 JSON

CVE-2021-27314

9.8
CRITICAL · CVSS 3.1 · EPSS 12.4% (pctl 96)

Patch early

EPSS 12.4% — above the 10% action threshold.

Description

SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.39% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2021-03-05
Last modified2026-06-17

Affected (1)

VendorProduct
doctor appointment system projectdoctor appointment system

References

→ the Explorer  ·  watch your stack  ·  NVD