CVE-2022-2297
SourceCodester Clinics Patient Management System unrestricted upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Se ha encontrado una vulnerabilidad, clasificada como crítica, en SourceCodester Clinics Patient Management System versión 2.0. Está afectada una función desconocida del archivo /pms/update_user.php?user_id=1. La manipulación del argumento profile_picture con la entrada (?php phpinfo();?) conlleva a una subida sin restricciones. Es posible lanzar el ataque de forma remota. La explotación ha sido divulgada al público y puede ser usada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-04 CVE Reserved
- 2022-07-12 CVE Published
- 2024-02-02 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Date | SRC |
---|---|---|
https://vuldb.com/?id.203178 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Clinic\'s Patient Management System Project Search vendor "Clinic\'s Patient Management System Project" | Clinic\'s Patient Management System Search vendor "Clinic\'s Patient Management System Project" for product "Clinic\'s Patient Management System" | 2.0 Search vendor "Clinic\'s Patient Management System Project" for product "Clinic\'s Patient Management System" and version "2.0" | - |
Affected
|