CVE-2022-24136

CRITICAL

Hospital Management System v1.0 - Code Injection

Title source: llm
STIX 2.1

Description

Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/kabirkhyrul/HMS/discussions/6

Scores

CVSS v3 9.8
EPSS 0.0032
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
hospital_management_system_project/hospital_management_system 1.0
Published Mar 31, 2022
Tracked Since Feb 18, 2026