CVE-2022-2297: SourceCodester Clinics Patient Management System unrestricted upload
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/updateuser.php?userid=1. The manipulation of the argument profilepicture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2297?
CVE-2022-2297 is classified as critical due to its potential for unauthorized remote code execution.
How do I fix CVE-2022-2297?
To fix CVE-2022-2297, update the Clinic's Patient Management System to a patched version that addresses this vulnerability.
What types of attacks can exploit CVE-2022-2297?
CVE-2022-2297 can be exploited to execute arbitrary PHP code through improper handling of the profile_picture parameter.
Which software versions are affected by CVE-2022-2297?
CVE-2022-2297 affects version 2.0 of the Clinic's Patient Management System.
Is there a proof of concept available for CVE-2022-2297?
Yes, there are proof of concept examples showing exploitation of CVE-2022-2297 in technical reports.