HIGHVulnerability

CVE-2026-85402

A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

Properties

severity
HIGH
score
7.3
cve_id
CVE-2026-85402
signal_observed_at
2026-09-15T21:20:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
published_at
2026-09-04T03:17:46.863
last_modified
2026-09-11T21:17:29.803

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85402 — Ninja Signal Threat Intelligence | Ninja Signal