SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter.
https://www.sourcecodester.com/php/18348/patients-waiting-area-queue-management-system.html