Vulnerabilities > Edoc Doctor Appointment System Project

DATE CVE VULNERABILITY TITLE RISK
2022-08-26 CVE-2022-36542 Unspecified vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
6.5
2022-08-26 CVE-2022-36543 SQL Injection vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
network
low complexity
edoc-doctor-appointment-system-project CWE-89
critical
9.8
2022-08-26 CVE-2022-36544 SQL Injection vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
network
low complexity
edoc-doctor-appointment-system-project CWE-89
critical
9.8
2022-08-26 CVE-2022-36545 SQL Injection vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
network
low complexity
edoc-doctor-appointment-system-project CWE-89
critical
9.8
2022-08-26 CVE-2022-36546 Cross-Site Request Forgery (CSRF) vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.
8.8
2022-08-26 CVE-2022-36547 Cross-site Scripting vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php.
6.1
2022-08-26 CVE-2022-36548 Cross-site Scripting vulnerability in Edoc-Doctor-Appointment-System Project Edoc-Doctor-Appointment-System 1.0.1
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php.
5.4