Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php
References
Link | Resource |
---|---|
https://www.sourcecodester.com/php-clinics-patient-management-system-source-code | Product |
https://drive.google.com/file/d/1m-wTfOL5gY3huaSEM3YPSf98qIrkl-TW/view?usp=sharing | Exploit Third Party Advisory |
https://github.com/RashidKhanPathan/CVE-2022-40471 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-10-31 09:15
Updated : 2022-11-01 10:00
NVD link : CVE-2022-40471
Mitre link : CVE-2022-40471
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
clinic\'s_patient_management_system_project
- clinic\'s_patient_management_system