CVE-2023-1059
published 2023-02-27CVE-2023-1059: A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file…
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.76%
50.9th percentile
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| doctors_appointment_system_project | doctors_appointment_system | — | — |
| chrome_chrome | — | — | |
| sourcecodester | doctors_appointment_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg47-49fq-q324: A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1
ghsa_unreviewed·2023-02-27
CVE-2023-1059 [HIGH] CWE-74 GHSA-hg47-49fq-q324: A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221824.
Chrome
Stable Channel Update for Desktop: CVE-2024-1077
vendor_chrome·2024-01-30·CVSS 8.8
CVE-2024-1077 [HIGH] Stable Channel Update for Desktop: CVE-2024-1077
Stable Channel Update for Desktop
CVE-2024-1077: Use after free in Network. Reported by Giulio Candreva with Microsoft Browser Security on 2023-12-12 [$5000][ 1511567 ] High CVE-2024-1060: Use after free in Canvas
Reported by Anonymous on 2023-12-14 [$3000][ 1514777 ] High CVE-2024-1059: Use after free in WebRTC
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/E1CHO/cve_hub/blob/main/edoc%20doctor%20appointment%20system/edoc%20doctor%20appointment%20system%20vlun3.pdfhttps://vuldb.com/?ctiid.221824https://vuldb.com/?id.221824https://vuldb.com/?submit.95222https://www.sourcecodester.com/https://github.com/E1CHO/cve_hub/blob/main/edoc%20doctor%20appointment%20system/edoc%20doctor%20appointment%20system%20vlun3.pdfhttps://vuldb.com/?ctiid.221824https://vuldb.com/?id.221824
2023-02-27
Published