CVE-2025-13122 – SourceCodester Patients Waiting Area Queue Management System api_patient_checkin.php getPatientAppointment sql injection
CVE ID : CVE-2025-13122
Published : Nov. 13, 2025, 6:15 p.m. | 43 minutes ago
Description : A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument appointmentID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…