CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-28568

Critical · CVSS 9.8

Sourcecodester Doctor's Appointment System — Unrestricted File Upload to Remote Code Execution (RCE)

CVSS
9.8
nvd
EPSS
4.06%
89th pct
KEV
No
Class
other
CWE-434

Description

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

Search profile — drives PoC discovery

Symbols image_uploadadministrator panelfile uploadwebshellimage path traversal
Keywords CVE-2022-28568Sourcecodester Doctor's Appointment Systemfile upload RCEunrestricted file uploadimage upload RCEadministrator panel exploitCWE-434Doctor Appointment System webshell
Versions: 1.0

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z