ZeroHour

CVE-2022-28568

PoC
CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

Vendors
simple doctor\'s appointment system project
Products
simple doctor\'s appointment system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.