HomeSecurityCVE-2026-19384 SourceCodester: Serious SQL injection in dating app

CVE-2026-19384 SourceCodester: Serious SQL injection in dating app

A serious SQL injection affects SourceCodester's Simple Doctors Appointment System 1.0 . SourceCodester's CVE-2026-19384 describes a remote, non-login attack with a publicly available exploit and database access.

The issue concerns the appointment management application distributed as a PHP/MySQL project. According to CVE Feed, the vulnerability has a CVSS score of 7.5 and is classified as CWE-89, while NVD has not yet filled in a description or official rating on the CVE page.

See also: SourceCodester Class Timetabling: SQL Injection vulnerability CVE-2026-14770

CVE-2026-19384 SourceCodester SQL injection

What CVE-2026-19384 Reveals SourceCodester

The technical report identifies the issue in the endpoint /doctors/admin/ajax.php?action=set_appointment and the id, which is sent with a POST request. The value is passed directly to SQL queries without adequate sanitization or strict validation.

This allows a remote visitor to modify the query and control the behavior of the database. The researcher's GitHub documents both blind SQL injection with logical conditions and a timing attack via MySQL SLEEP.

The test was done with the sqlmap tool and does not require an account or prior authorization. Based on the available evidence, an attacker can confirm the vulnerability, read data, and, depending on the database permissions, modify or delete records.

Remote SQL injection in an appointment application

The implications for application installations

Simple Doctors Appointment System manages patient, doctor, and appointment data. Successful exploitation could expose personal data, corrupt the appointment calendar, or disrupt the application. The actual extent depends on the database schema and MySQL account permissions.

The public report does not prove an active exploit online, nor does it provide a patch. Therefore, the availability of a technical demonstration should not be confused with a confirmed attack campaign. However, the combination of remote access, lack of required privileges, and a published exploit increases the risk.

See also: khunt: SQL Injection in Oracle leads to SYSTEM access

What should administrators do?

Those using version 1.0 should immediately limit endpoint exposure by only allowing access from trusted networks or via VPN where possible. In addition, log files should be checked for unusual POST requests to set_appointment, long response delays, and duplicate values ​​in the id.

At the code level, safe debugging requires prepared statements and bound parameters, not simple character substitution. The id should be checked as an identifier with the expected numeric range, and the database account should have the minimum necessary privileges and not use administrator privileges.

Defense measures for CVE-2026-19384 SourceCodester

Controlling and mitigating SQL injection

The search for clues should be done at the application, server, and database levels. Repeated requests to the specific endpoint, unusual id, responses with different times, and SQL errors can help identify tests. Logs should be maintained before any changes are made so that investigation can be performed.

If there are signs of a breach, the application and database credentials need to be changed, the system should be checked for unknown accounts, and the records compared to a recent backup. The restore should be done in a clean environment, after first examining the installation files and other applications on the same server.

Using an application firewall can temporarily reduce some attack patterns, but it is not a substitute for fixing the code. Rules should be tested carefully because a blanket price ban can affect legitimate appointments or hide the real problem without eliminating it.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Because the app can store health and contact information, any potential incident needs to be documented and carefully assessed by the organization's manager. The priority is to limit access and preserve the data, without deleting traces that may be needed for auditing.

The SourceCodester website does not display a related announcement or specific patch on its main page. Administrators should monitor the project for updates, maintain backups, and consider reinstalling from a verified package only when there is a clear instruction.

See also: Prompt Injection: AI agents make crypto payments without authorization

Application protection from SQL injection

CVE -2026-19384 SourceCodester affects a publicly available application project, but available evidence does not yet support an official patch. Until a clear solution is released, isolation of the installation, request monitoring, and restriction of database privileges are the main defenses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS