HIGH
CVE-2026-19231
CVSS
7.3
Description
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Weakness (CWE)
CWE-74
Injection
CWE-89
SQL Injection
EPSS Score
0.26%
Probability of exploitation in next 30 days
18.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.