PT-2026-33708 · Unknown · Rickxy Hospital Management System

Wacool

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6602

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rickxy Hospital Management System versions prior to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4
Description An unrestricted file upload issue exists in the admin panel. The problem occurs in the file '/backend/admin/his admin account.php' where manipulation of the ad dpic argument allows remote attackers to upload files without restrictions.
Recommendations Update to a version later than 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. As a temporary workaround, restrict access to the file '/backend/admin/his admin account.php' or avoid using the ad dpic argument.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-6602

Affected Products

Rickxy Hospital Management System