Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
View the template here CVE-2021-27320.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2021-27320