EXPOSURES › CVE-2022-28568
CVE-2022-28568
CRITICAL
DETAIL
SourceNVD · cve
Published2022-05-04
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-28568 ↗
⚡ RCE
SHAME 50/100
rce
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.