What is CVE-2026-19231?
A SQL injection vulnerability was discovered in the `/admin/ajax.php?action=delete_appointment` file of SourceCodester Simple Doctors Appointment System 1.0. This allows remote attackers to manipulate the ID parameter to gain unauthorized database access. Immediate patching or implementing input validation is recommended.
Azərbaycanca: SourceCodester Simple Doctors Appointment System 1.0 versiyasının `/admin/ajax.php?action=delete_appointment` faylında SQL injection zəifliyi aşkarlanıb. Uzaqdan hücumçu ID parametrini manipulyasiya edərək verilənlər bazasına icazəsiz giriş əldə edə bilər. Sistem dərhal yenilənməli və ya giriş yoxlamaları tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which version of SourceCodester Simple Doctors Appointment System is affected by CVE-2026-19231?
Version 1.0 of SourceCodester Simple Doctors Appointment System is affected.
What can a remote attacker achieve by exploiting CVE-2026-19231?
A remote attacker can manipulate the ID parameter in the `/admin/ajax.php?action=delete_appointment` file to gain unauthorized database access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.