PatchSiren cyber security CVE debrief
CVE-2026-105468 girishsaraf CVE debrief
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The vulnerability allows for remote sql injection attacks, which could lead to unauthorized access or data manipulation. Defenders should prioritize verification and patching to prevent exploitation.
- Vendor
- girishsaraf
- Product
- Online-Appointment-Booking-System
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for the Online-Appointment-Booking-System should assess exposure and prioritize verification and patching to prevent exploitation. Defenders should also review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
The vulnerability allows for remote sql injection attacks, which could lead to unauthorized access or data manipulation. Defenders should prioritize verification and patching to prevent exploitation.
- Verify affected version and apply patches or workarounds to prevent exploitation
- Restrict access to the Admin/mlogin.php file to trusted users only
- Implement additional security measures to detect and prevent sql injection attacks
Technical summary
The vulnerability affects the Online-Appointment-Booking-System up to version f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The Login Handler component in the file Admin/mlogin.php is vulnerable to sql injection through manipulation of the uname/pass argument. The attack may be initiated remotely. Defenders should prioritize verifying the affected version and applying patches or workarounds to prevent exploitation. The vulnerability allows for sql injection attacks, which could lead to unauthorized access or data manipulation.
Defensive priority
Defenders should prioritize verifying the affected version and applying patches or workarounds to prevent exploitation.
Recommended defensive actions
- Verify the affected version of Online-Appointment-Booking-System and apply patches or workarounds to prevent exploitation
- Restrict access to the Admin/mlogin.php file to trusted users only
- Implement additional security measures to detect and prevent sql injection attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- whoShouldCare
- Defenders responsible for the Online-Appointment-Booking-System should assess exposure and prioritize verification and patching to prevent exploitation. Defenders should also review compensating controls for exposed and
Evidence notes
The vulnerability was found in the Online-Appointment-Booking-System up to version f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected component is the Login Handler in the file Admin/mlogin.php. The vulnerability allows for sql injection through manipulation of the uname/pass argument.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105468 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105468
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105468 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105468
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105468.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413614
Supplemental source - vdb-entry, technical-description
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413614/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105468
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/984333
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/girishsaraf/Online-Appointment-Booking-System/issues/6
Supplemental source - exploit, issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/girishsaraf/Online-Appointment-Booking-System/
Supplemental source - product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.