CVE-2022-2297

A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clinic\'s_patient_management_system_project:clinic\'s_patient_management_system:2.0:*:*:*:*:*:*:*

History

07 Nov 2023, 03:46

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
First Time Clinic\'s Patient Management System Project
Clinic\'s Patient Management System Project clinic\'s Patient Management System
CPE cpe:2.3:a:clinic\'s_patient_management_system_project:clinic\'s_patient_management_system:2.0:*:*:*:*:*:*:*
References
  • {'url': "https://github.com/CyberThoth/CVE/blob/8c6b66919be1bd66a54c16cc27cbdd9793221d3e/CVE/Clinic's%20Patient%20Management%20System/Unrestricted%20file%20upload%20(RCE)/POC.md", 'name': "https://github.com/CyberThoth/CVE/blob/8c6b66919be1bd66a54c16cc27cbdd9793221d3e/CVE/Clinic's%20Patient%20Management%20System/Unrestricted%20file%20upload%20(RCE)/POC.md", 'tags': [], 'refsource': 'MISC'}
  • () https://github.com/CyberThoth/CVE/blob/8c6b66919be1bd66a54c16cc27cbdd9793221d3e/CVE/Clinic%27s%20Patient%20Management%20System/Unrestricted%20file%20upload%20%28RCE%29/POC.md -
References (MISC) https://vuldb.com/?id.203178 - (MISC) https://vuldb.com/?id.203178 - Exploit, Third Party Advisory

12 Jul 2022, 17:44

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-12 17:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-2297

Mitre link : CVE-2022-2297

CVE.ORG link : CVE-2022-2297


JSON object : View

Products Affected

clinic\'s_patient_management_system_project

  • clinic\'s_patient_management_system
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type