PT-2026-29194 · Sourcecodester · Simple Doctors Appointment System

Dyh18

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-5181

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Doctors Appointment System version 1.0
Description A flaw exists in the processing of files, specifically /doctors appointment/admin/ajax.php?action=save category. Manipulation of the img argument allows for unrestricted file uploads. This issue can be exploited remotely. The details of the exploit have been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-5181

Affected Products

Simple Doctors Appointment System