Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105469— girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection

Quick assessment

Affected
girishsaraf Online-Appointment-Booking-System
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 girishsaraf 的 Online-Appointment-Booking-System(在线预约系统)中,从初始提交至 f427b4757128ca253d33d0cc4e87bbb9c999a4d5 版本期间,存在一个安全漏洞。该漏洞影响组件 AJAX Endpoint 中文件 get_town.php 的未知代码部分。通过对参数 countryid/townid/cid/didval/cidval 进行操纵,可能导致 SQL 注入攻击。攻击者可远程发起该攻击。 目前,该漏洞的利用方式已被公开披露,并

CVSS 7.3 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105469

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
girishsaraf Online-Appointment-Booking-System f427b4757128ca253d33d0cc4e87bbb9c999a4d5 cpe:2.3:a:girishsaraf:online-appointment-booking-system:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-105469

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105469

请登录查看更多情报信息。

Other References for CVE-2026-105469 (5)

Same Patch Batch · girishsaraf · 2026-10-05 · 4 CVEs total

CVE-2026-105387 7.3 HIGH girishsaraf Online-Appointment-Booking-System Patient Login cover.php mysqli_query sql inj
CVE-2026-105468 7.3 HIGH girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection
CVE-2026-105470 7.3 HIGH girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus.php mysqli_q

IV. Related Vulnerabilities

V. Comments for CVE-2026-105469

No comments yet


Leave a comment