CVE-2025-13122 – SourceCodester Patients Waiting Area Queue Management System api_patient_checkin.php getPatientAppointment sql injection

CVE ID : CVE-2025-13122

Published : Nov. 13, 2025, 6:15 p.m. | 43 minutes ago

Description : A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument appointmentID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

Severity: 7.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه