A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2022-07-12T16:22:14

Updated: 2022-07-12T16:22:14

Reserved: 2022-07-04T00:00:00


Link: CVE-2022-2297

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-07-12T17:15:07.493

Modified: 2023-11-07T03:46:27.360


Link: CVE-2022-2297

JSON object: View

cve-icon Redhat Information

No data.

CWE