PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105468 girishsaraf CVE debrief

A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The vulnerability allows for remote sql injection attacks, which could lead to unauthorized access or data manipulation. Defenders should prioritize verification and patching to prevent exploitation.

Vendor
girishsaraf
Product
Online-Appointment-Booking-System
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-08
Advisory published
2026-10-05
Advisory updated
2026-10-08

Who should care

Defenders responsible for the Online-Appointment-Booking-System should assess exposure and prioritize verification and patching to prevent exploitation. Defenders should also review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

The vulnerability allows for remote sql injection attacks, which could lead to unauthorized access or data manipulation. Defenders should prioritize verification and patching to prevent exploitation.

  • Verify affected version and apply patches or workarounds to prevent exploitation
  • Restrict access to the Admin/mlogin.php file to trusted users only
  • Implement additional security measures to detect and prevent sql injection attacks

Technical summary

The vulnerability affects the Online-Appointment-Booking-System up to version f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The Login Handler component in the file Admin/mlogin.php is vulnerable to sql injection through manipulation of the uname/pass argument. The attack may be initiated remotely. Defenders should prioritize verifying the affected version and applying patches or workarounds to prevent exploitation. The vulnerability allows for sql injection attacks, which could lead to unauthorized access or data manipulation.

Defensive priority

Defenders should prioritize verifying the affected version and applying patches or workarounds to prevent exploitation.

Recommended defensive actions

  • Verify the affected version of Online-Appointment-Booking-System and apply patches or workarounds to prevent exploitation
  • Restrict access to the Admin/mlogin.php file to trusted users only
  • Implement additional security measures to detect and prevent sql injection attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • whoShouldCare
  • Defenders responsible for the Online-Appointment-Booking-System should assess exposure and prioritize verification and patching to prevent exploitation. Defenders should also review compensating controls for exposed and

Evidence notes

The vulnerability was found in the Online-Appointment-Booking-System up to version f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected component is the Login Handler in the file Admin/mlogin.php. The vulnerability allows for sql injection through manipulation of the uname/pass argument.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105468 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105468

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105468 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105468

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105468.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/413614

    Supplemental source - vdb-entry, technical-description

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/413614/cti

    Supplemental source - signature, permissions-required

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/cve/CVE-2026-105468

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/submit/984333

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/girishsaraf/Online-Appointment-Booking-System/issues/6

    Supplemental source - exploit, issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/girishsaraf/Online-Appointment-Booking-System/

    Supplemental source - product

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.