CVE-2026-5181: SourceCodester Simple Doctors Appointment System ajax.php unrestricted upload
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctorsappointment/admin/ajax.php?action=savecategory. Such manipulation of the argument img leads to unrestricted upload. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5181?
CVE-2026-5181 has a high severity rating due to its potential for unrestricted file uploads.
How do I fix CVE-2026-5181?
To fix CVE-2026-5181, implement proper validation and sanitization for uploaded files in the ajax.php script.
What are the potential impacts of CVE-2026-5181?
CVE-2026-5181 could allow attackers to upload malicious files leading to arbitrary code execution on the server.
Which version of SourceCodester Simple Doctors Appointment System is affected by CVE-2026-5181?
CVE-2026-5181 affects SourceCodester Simple Doctors Appointment System up to and including version 1.0.
Where is the vulnerable file in CVE-2026-5181 located?
The vulnerable file for CVE-2026-5181 is located at /doctors_appointment/admin/ajax.php?action=save_category.