CVE-2025-65358: Hashenudara Edoc-Doctor-Appointment-System

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

Affected products

  • Hashenudara Edoc-Doctor-Appointment-System: version 1.0.1 only

Published 2025-12-02. Last modified 2026-06-17.