Security Advisory

CVE-2022-28568

9.8
CRITICAL

Vulnerability Description

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Published Date May 4, 2022
Official Source NIST NVD Advisory