vendor:
Clinic Management System
by:
BKpatron
8.8
CVSS
HIGH
Unauthenticated File Upload Vulnerability
434
CWE
Product Name: Clinic Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:clinic_management_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win 10
2020
Clinic Management System 1.0 – Unauthenticated Remote Code Execution
Clinic Management System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously crafted PHP file.
Mitigation:
Ensure that all user input is validated and sanitized before being used in any file upload operations.