Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2297
HistoryJul 12, 2022 - 5:15 p.m.

Design/Logic Flaw

2022-07-1217:15:00
PRIOn knowledge base
www.prio-n.com
5
vulnerability
critical
sourcecodester clinics
patient management system
file upload
remote attack
exploit disclosed

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

42.9%

A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

42.9%

Related for PRION:CVE-2022-2297