Unknown · Clinic'S Patient Management System · CVE-2022-40471
**Name of the Vulnerable Software and Affected Versions**
Clinic's Patient Management System version 1.0
**Description**
The issue allows an attacker to upload an arbitrary PHP webshell via the profile picture upload functionality in `users.php`. This enables remote code execution.
**Recommendations**
For Clinic's Patient Management System version 1.0, consider disabling the profile picture upload functionality in `users.php` until a patch is available to prevent the upload of arbitrary PHP webshells. Restrict access to the `users.php` file to minimize the risk of exploitation. Avoid using the profile picture upload feature until the issue is resolved.