Beauty Parlour Management System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Beauty Parlour Management System version 1.1. The issue arises in the 'aptnumber' parameter of the '/appointment-detail.php' endpoint, allowing attackers to execute crafted SQL statements that could access sensitive database information. This vulnerability can be exploited by ordinary users who have registered through the 'signup' function.

Impact

Exploitation of this vulnerability could lead to unauthorized access to database information, with the potential to obtain database access rights or even DBA permissions.

Reproduction

The vulnerability can be reproduced by sending a crafted SQL injection payload through the 'aptnumber' parameter in the '/appointment-detail.php' endpoint. This can be done manually or using automated tools like sqlmap. The injection can be verified by extracting database information, such as the current database name, or by using time-based payloads to confirm the injection's effectiveness.

Added: May 8, 2026, 9:57 PM
Updated: May 8, 2026, 9:57 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
2.5
exploitability
4.6
remediation
0.0
relevance
7.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.