CVE-2026-105471: SQL Injection in girishsaraf Online-Appointment-Booking-System
Description
CVE-2026-105471 is a medium-severity SQL injection vulnerability in the girishsaraf Online-Appointment-Booking-System affecting the signup.php file's Registration Handler component. The flaw allows remote attackers to manipulate the 'fname' argument to execute SQL injection attacks. The product uses a rolling release model, so specific affected or fixed versions are not available. The vulnerability has been publicly disclosed with exploit code released, but the vendor has not yet responded or issued a fix.
CVSS v4.0
Score 6.9medium
Affected software
girishsaraf
Online-Appointment-Booking-System
cpe:2.3:a:girishsaraf:online-appointment-booking-system:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an SQL injection in the 'fname' parameter of the signup.php file within the Registration Handler component of the girishsaraf Online-Appointment-Booking-System. An attacker can remotely exploit this flaw to manipulate SQL queries, potentially compromising the database. The product follows a rolling release model, making it difficult to specify exact affected versions. Although the issue was reported early, the vendor has not provided a patch or response. Public exploit code is available, increasing the risk of exploitation.
Potential Impact
Successful exploitation of this SQL injection vulnerability can allow an attacker to execute arbitrary SQL commands on the backend database, potentially leading to unauthorized data access, data modification, or other database impacts. The vulnerability is remotely exploitable without authentication and requires no user interaction. The CVSS 4.0 base score is 6.9 (medium severity), reflecting the moderate impact and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or issued a fix, users should monitor for updates from the vendor. Until a patch is available, consider applying application-layer mitigations such as input validation, parameterized queries, or web application firewalls to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-10-05T14:58:23.462Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac433e22cdf04f6564738d3
Added to database: 10/05/2026, 23:33:54 UTC
Last enriched: 10/05/2026, 23:48:39 UTC
Last updated: 10/05/2026, 23:48:59 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.