Loading market data...
← Back to CVE feed

CVE-2026-5181

MEDIUM CVSS 6.3 View on NVD ↗

Description

A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_category. Such manipulation of the argument img leads to unrestricted upload. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Published: Mar 31, 2026 05:16 UTC Modified: Mar 31, 2026 05:16 UTC