Skip to content
COOEY

EXPOSURES › CVE-2022-28568

CVE-2022-28568

CRITICAL
DETAIL
SourceNVD · cve Published2022-05-04 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-28568 ↗
⚡ RCE SHAME 50/100 rce

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.