CVE-2026-105469

Source
https://cve.org/CVERecord?id=CVE-2026-105469
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105469.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105469
Published
2026-10-05T22:15:17Z
Modified
2026-10-08T02:49:18Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection
Details

A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105469.json"
}
References

Affected packages

Git / github.com/girishsaraf/online-appointment-booking-system

Affected ranges

Type
GIT
Repo
https://github.com/girishsaraf/online-appointment-booking-system
Events

Affected versions

Other
f427b4757128ca253d33d0cc4e87bbb9c999a4d5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105469.json"