PT-2024-39093 · Sourcecodester · Clinic'S Patient Management System

Guru

·

Published

2024-09-07

·

Updated

2024-09-10

·

CVE-2024-8555

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SourceCodester Clinics Patient Management System version 2.0
Description: A vulnerability exists in the system, allowing for an open redirect. The issue is related to the manipulation of the goto page argument in an unknown function of the file congratulations.php. This can be exploited remotely.
Recommendations: For version 2.0, consider restricting access to the congratulations.php file or the goto page argument to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-8555

Affected Products

Clinic'S Patient Management System