PT-2026-33708 · Unknown · Rickxy Hospital Management System
Wacool
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6602
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rickxy Hospital Management System versions prior to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4
Description
An unrestricted file upload issue exists in the admin panel. The problem occurs in the file '/backend/admin/his admin account.php' where manipulation of the
ad dpic argument allows remote attackers to upload files without restrictions.Recommendations
Update to a version later than 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4.
As a temporary workaround, restrict access to the file '/backend/admin/his admin account.php' or avoid using the
ad dpic argument.Exploit
Fix
Unrestricted File Upload
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rickxy Hospital Management System