Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ihexcoder

#24383of 53,611
9.8Total CVSS
Vulnerabilities · 1
PT-2022-25396
9.8
2022-10-31
Unknown · Clinic'S Patient Management System · CVE-2022-40471
**Name of the Vulnerable Software and Affected Versions** Clinic's Patient Management System version 1.0 **Description** The issue allows an attacker to upload an arbitrary PHP webshell via the profile picture upload functionality in `users.php`. This enables remote code execution. **Recommendations** For Clinic's Patient Management System version 1.0, consider disabling the profile picture upload functionality in `users.php` until a patch is available to prevent the upload of arbitrary PHP webshells. Restrict access to the `users.php` file to minimize the risk of exploitation. Avoid using the profile picture upload feature until the issue is resolved.