CVE-2022-28568
PoC —CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
- Vendors
- simple doctor\'s appointment system project
- Products
- simple doctor\'s appointment system
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.