CVE-2026-19839: SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function savedoctor of the file /savefile.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19839?
The severity of CVE-2026-19839 is rated as medium with a score of 4.7.
What is CVE-2026-19839 vulnerability about?
CVE-2026-19839 is a vulnerability in the SourceCodester Simple Doctors Appointment System that allows unrestricted file upload through the save_doctor function.
How do I fix CVE-2026-19839?
To fix CVE-2026-19839, implement proper file validation and restrict file types in the save_doctor function of save_file.php.
Can CVE-2026-19839 be exploited remotely?
Yes, CVE-2026-19839 can be exploited remotely, allowing attackers to upload malicious files.
What are the potential impacts of CVE-2026-19839?
The potential impacts of CVE-2026-19839 include unauthorized file uploads that can lead to further exploitation like malware deployment.