CVE-2022-28568

CRITICAL

Sourcecodester Doctor's Appointment System 1.0 - RCE

Title source: llm
STIX 2.1

Description

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

References (3)

Core 3
Core References
Broken Link x_refsource_misc
http://sourcecodetester.com
Broken Link x_refsource_misc
http://doctors.com

Scores

CVSS v3 9.8
EPSS 0.0153
EPSS Percentile 81.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
simple_doctor\'s_appointment_system_project/simple_doctor\'s_appointment_system 1.0
Published May 04, 2022
Tracked Since Feb 18, 2026