CVE-2022-28568
Critical · CVSS 9.8Sourcecodester Doctor's Appointment System — Unrestricted File Upload to Remote Code Execution (RCE)
- CVSS
- 9.8
- nvd
- EPSS
- 4.06%
- 89th pct
- KEV
- No
- Class
- other
- CWE-434
Description
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Search profile — drives PoC discovery
Symbols image_uploadadministrator panelfile uploadwebshellimage path traversal
Keywords CVE-2022-28568Sourcecodester Doctor's Appointment Systemfile upload RCEunrestricted file uploadimage upload RCEadministrator panel exploitCWE-434Doctor Appointment System webshell
Versions: 1.0
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z