CVE-2026-5180

A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=login2. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Configurations

No configuration.

History

24 Apr 2026, 18:11

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una falla en SourceCodester Simple Doctors Appointment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /admin/ajax.PHP?action=login2. Esta manipulación del argumento email causa inyección SQL. El ataque es posible de llevar a cabo de forma remota. El exploit ha sido publicado y puede ser usado.

31 Mar 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 05:16

Updated : 2026-04-29 01:00


NVD link : CVE-2026-5180

Mitre link : CVE-2026-5180

CVE.ORG link : CVE-2026-5180


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')