Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90805— subhajitkhan online-clinic-management-system doctorlogin.php sql injection

Quick assessment

Affected
subhajitkhan online-clinic-management-system
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 subhajitkhan 的 online-clinic-management-system(在线诊所管理系统)中发现了漏洞,影响版本范围直到提交 e9ee77a8827a1446220fa07ee693dc4d9a29a578。该漏洞影响 文件中的未知部分。通过对参数 或 进行操纵,可能引发 SQL 注入漏洞。该攻击可远程执行,且相关利用方式(exploit)已经公开,可能被攻击者利用。该产品的发布模式为滚动发布(rolling release)以支持持续交付,因此无法获取受影响版本或已修复版本的具体版本信息

CVSS 7.3 · High

Possible ATT&CK Techniques 1 AI

T1190.009

Affected Version Matrix 1

VendorProduct Version RangeStatus
subhajitkhan online-clinic-management-system e9ee77a8827a1446220fa07ee693dc4d9a29a578 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90805

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
subhajitkhan online-clinic-management-system doctorlogin.php sql injection
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
subhajitkhan online-clinic-management-system e9ee77a8827a1446220fa07ee693dc4d9a29a578 cpe:2.3:a:subhajitkhan:online-clinic-management-system:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-90805

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90805

登录查看更多情报信息。

Proof of Concept for CVE-2026-90805 (1)

Other References for CVE-2026-90805 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-90805

No comments yet


Leave a comment