A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.
History

Fri, 07 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-07T00:00:00.000Z

Updated: 2025-11-07T17:55:22.678Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-07T18:15:36.780

Modified: 2025-11-07T18:15:36.780

Link: CVE-2025-63718

cve-icon Redhat

No data.