vendor:
Clinic Management System
by:
BKpatron
8.8
CVSS
HIGH
Unauthenticated File Upload Vulnerability
434
CWE
Product Name: Clinic Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:clinic_management_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win 10
2020
Clinic Management System 1.0 – Authenticated Arbitrary File Upload
Clinic Management System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously crafted PHP file.
Mitigation:
Restrict access to the vulnerable file 'manage_website.php' and ensure that only authenticated users can access it.